Week 8 - 2026 Weekly Digest

16 Feb 2026 – 22 Feb 2026 • Published: 23 Feb 2026

CVE News Ransomware 8Bit Content Week 8 2026

Critical CVEs

CVE-2026-1405 — Arbitrary File Upload CVSS 9.8

WordPress Slider Future

The Slider Future plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'slider_future_handle_image_upload' function in all versions up to, and including, 1.0.5. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2026-1490 — Unauthorized Plugin Installation CVSS 9.8

WordPress CleanTalk

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS (PTR record) spoofing on the 'checkWithoutToken' function in all versions up to, and including, 6.71. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. Note: This is only exploitable on sites with an invalid API key.

CVE-2026-27574 — Sandbox Escape CVSS 9.9

Node.js OneUptime

OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a security mechanism) to execute user-supplied code, allowing trivial sandbox escape via a well-known one-liner that grants full access to the underlying process. Because the probe runs with host networking and holds all cluster credentials (ONEUPTIME_SECRET, DATABASE_PASSWORD, REDIS_PASSWORD, CLICKHOUSE_PASSWORD) in its environment variables, and monitor creation is available to the lowest role (ProjectMember) with open registration enabled by default, any anonymous user can achieve full cluster compromise in about 30 seconds. This issue has been fixed in version 10.0.5.

Top Security News

Predator spyware hooks iOS SpringBoard to hide mic, camera activity News

The iOS Predator spyware is capable of bypassing the visual indicators for camera and microphone activation, enabling covert surveillance of the user without their awareness. It achieves this by leveraging kernel-level access and manipulating specific SpringBoard functions.

Source: BleepingComputer

Russia stepping up hybrid attacks, preparing for long standoff with West, Dutch intelligence warns News

Russia’s intensifying cyberattacks, sabotage and covert influence operations across Europe show the Kremlin is preparing for a prolonged confrontation with the West, Dutch intelligence agencies said in a report published this week. In a joint assessment by the General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD), the Dutch agencies warned that while a direct military clash between Russia and NATO remains unlikely, it is no longer unthinkable.

Source: TheRecord

Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning News

Anthropic has launched Claude Code Security, an AI system that detects code vulnerabilities and suggests automatic patches. Its debut caused cybersecurity company stocks to decline, amid concerns over a potential impact on traditional security solutions.

Source: TheHackerNews

Ransomware Activity

ABAR S.p.A. Ransomware

The threat actor Qilin claims responsibility for a ransomware attack against the victim in the Manufacturing sector on February 20.

Elgon Cosmetic Ransomware

The threat actor Spacebears claims responsibility for a ransomware attack against the victim in the Pharmacy sector on February 18.

Femar.it Ransomware

The threat actor Tengu claims responsibility for a ransomware attack against the victim in the Information Technologies sector on February 18.

Casartigiani Ransomware

The threat actor Qilin claims responsibility for a ransomware attack against the victim in the Non-Governmental Organizations sector on February 16.

Icat Food SpA Ransomware

The threat actor Akira claims responsibility for a ransomware attack against the victim in the Food and drinks businesses sector on February 16.

wiproferretto.com Ransomware

The threat actor Dragonforce claims responsibility for a ransomware attack against the victim in the Information Technologies sector on February 16.

iSMA CONTROLLI Ransomware

The threat actor Akira claims responsibility for a ransomware attack against the victim in the High-tech sector on February 16.