Week 8 - 2026 Weekly Digest
16 Feb 2026 – 22 Feb 2026 • Published: 23 Feb 2026
Critical CVEs
CVE-2026-1405 — Arbitrary File Upload CVSS 9.8The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVE-2026-1490 — Unauthorized Plugin Installation CVSS 9.8The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. Note: This is only exploitable on sites with an invalid API key.
CVE-2026-27574 — Sandbox Escape CVSS 9.9OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to execute user-supplied code, allowing trivial sandbox escape via a well-known one-liner that grants full access to the underlying process. Because the probe runs with host networking and holds all cluster credentials (ONEUPTIME_SECRET, DATABASE_PASSWORD, REDIS_PASSWORD, CLICKHOUSE_PASSWORD) in its environment variables, and monitor creation is available to the lowest role (ProjectMember) with open registration enabled by default, any anonymous user can achieve full cluster compromise in about 30 seconds. This issue has been fixed in version 10.0.5.
Top Security News
Predator spyware hooks iOS SpringBoard to hide mic, camera activity NewsThe iOS Predator spyware is capable of bypassing the visual indicators for camera and microphone activation, enabling covert surveillance of the user without their awareness. It achieves this by leveraging kernel-level access and manipulating specific SpringBoard functions.
Russia stepping up hybrid attacks, preparing for long standoff with West, Dutch intelligence warns NewsRussia’s intensifying cyberattacks, sabotage and covert influence operations across Europe show the Kremlin is preparing for a prolonged confrontation with the West, Dutch intelligence agencies said in a report published this week. In a joint assessment by the General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD), the Dutch agencies warned that while a direct military clash between Russia and NATO remains unlikely, it is no longer unthinkable.
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning NewsAnthropic has launched Claude Code Security, an AI system that detects code vulnerabilities and suggests automatic patches. Its debut caused cybersecurity company stocks to decline, amid concerns over a potential impact on traditional security solutions.
Ransomware Activity
ABAR S.p.A. RansomwareThe threat actor Qilin claims responsibility for a ransomware attack against the victim in the Manufacturing sector on February 20.
Elgon Cosmetic RansomwareThe threat actor Spacebears claims responsibility for a ransomware attack against the victim in the Pharmacy sector on February 18.
Femar.it RansomwareThe threat actor Tengu claims responsibility for a ransomware attack against the victim in the Information Technologies sector on February 18.
Casartigiani RansomwareThe threat actor Qilin claims responsibility for a ransomware attack against the victim in the Non-Governmental Organizations sector on February 16.
Icat Food SpA RansomwareThe threat actor Akira claims responsibility for a ransomware attack against the victim in the Food and drinks businesses sector on February 16.
wiproferretto.com RansomwareThe threat actor Dragonforce claims responsibility for a ransomware attack against the victim in the Information Technologies sector on February 16.
iSMA CONTROLLI RansomwareThe threat actor Akira claims responsibility for a ransomware attack against the victim in the High-tech sector on February 16.



