Exploit code has been released for CVE 2025 64155, a critical command injection vulnerability affecting Fortinet FortiSIEM devices, and is considered actively exploitable.
Vulnerability Details
Affected Product: Fortinet FortiSIEM
Identifier: CVE-2025-64155
Exploitation Status: Exploit Code Released
Risk & Impact
Triage: High Urgency
Attack Vector: OS Command Injection
Ease of Exploit: High, due to public exploit code
Action Plan
Immediate Action: Upgrade to the latest version of FortiSIEM
Workaround: Implement strict input validation and sanitization to prevent command injection
Detection: Monitor for suspicious command execution patterns and unauthorized system access
Relevant professional terms
Command Injection
A type of security vulnerability that allows an attacker to execute arbitrary commands on the host operating system.
Exploit Code
A piece of software, a chunk of data, or a sequence of commands that takes advantage of a bug or vulnerability to cause unintended or unanticipated behavior to occur on computer hardware, software, or something electronic.
A critical unauthenticated Remote Code Execution (RCE) vulnerability, CVE-2026-21858, has been discovered in n8n, potentially impacting an estimated 100,000 servers globally. There are currently no official workarounds available, and users are advised to upgrade to the latest version.
Vulnerability Details
Affected Product: n8n versions prior to 1.121.0
Identifier: CVE-2026-21858
CVSS Score: 10.0 (Critical)
Exploitation Status: Proof of concept (PoC) exploit code is publicly available.
Risk & Impact
Triage: Immediate upgrade is required due to the potential for complete compromise of automation infrastructure.
Attack Vector: The vulnerability stems from a Content-Type confusion flaw in n8n's webhook and file-handling logic, allowing attackers to send crafted HTTP requests to bypass authentication and achieve remote code execution.
Ease of Exploit: Easy, due to low attack complexity and no required privileges.
Action Plan
Immediate Action: Upgrade n8n to version 1.121.0 or later.
Workaround: Restrict or disable publicly accessible webhook and form endpoints as a temporary mitigation.
Detection: Monitor for unusual file access patterns, unexpected workflow executions, and path traversal attempts in server logs.
Relevant professional terms
Remote Code Execution (RCE)
A vulnerability that allows an attacker to execute arbitrary code on a target system.
CVSS Score
A numerical representation of the severity of a security vulnerability, with a score of 10.0 being the most critical.
Shipping tech company Bluspark exposed its platform and customer data due to multiple vulnerabilities, including plaintext password storage. This exposure could lead to unauthorized access and potential compromise of sensitive shipping and customer information.
Attack Overview
Attack Path: Unauthenticated API access, plaintext password storage.
Impact Assessment
Data Stolen: User credentials and shipment records dating back to 2007.
Strategic Takeaway
Storing sensitive credentials in plaintext poses a significant risk, emphasizing the need for robust encryption and authentication mechanisms.
Relevant professional terms
Plaintext Password
Storing passwords in an unencrypted format, making them easily readable if accessed.
Unauthenticated API
An API that does not require authentication, allowing anyone to access its data and functionality.
The Black Lotus Labs team null routed traffic to over 550 command and control nodes associated with the AISURU Kimwolf botnet since early October 2025. These botnets have emerged as significant threats, compromising millions of devices.
Key TTPs
Initial Access: Exploiting vulnerabilities in residential proxy networks and pre-installed malware on Android devices.
Execution: Uses NDK to compile botnet with DDoS, proxy forwarding, reverse shell, and file management functions.
Defense Evasion: Employs Stack XOR encryption, DNS over TLS (DoT), and EtherHiding technology.
Campaign Analysis
The Kimwolf botnet is an Android variant of AISURU and has infected over 1.8 million devices. It has been used to launch DDoS attacks and generate revenue through proxy services.
Targeting & Infrastructure
Target Profile: Primarily Android TV boxes and other IoT devices in residential networks.
Infrastructure: Utilizes over 550 C2 servers and a network of compromised devices across multiple global time zones.
The Sicarii group emerged in December 2025 as a Ransomware-as-a-Service (RaaS) operation, advertising its services on underground platforms. The group uses Israeli symbolism and messaging, but technical analysis suggests possible false-flag behavior.
Key TTPs
Initial Access: Likely via phishing or exploiting exposed services.
Execution: Data encryption using AES-GCM.
Defense Evasion: Anti-VM checks and geo-fencing to avoid Israeli systems.
Campaign Analysis
Sicarii is distinguished by its explicit use of Israeli symbolism, which deviates from established ransomware norms. The group focuses on small businesses to reduce scrutiny.
Targeting & Infrastructure
Target Profile: Small to mid-sized organizations across various sectors.
RaaS: Ransomware as a Service, a business model where ransomware developers lease their ransomware to affiliates.
AES-GCM: Advanced Encryption Standard - Galois/Counter Mode, a widely used symmetric-key encryption algorithm providing confidentiality and data integrity.
A widespread Verizon Wireless outage on January 14, 2026, left customers across the US without cellular service, with many phones stuck in SOS mode. The outage, which impacted voice and data services, prompted the company to offer account credits to affected users.
Key Findings
The outage began around noon ET, with Downdetector logging over 171,000 reports.
Many iPhone users saw their devices switch to SOS mode, indicating a lack of cellular network connection.
The outage affected major cities across the US, including New York City, Chicago, and Washington D.C..
The Bottom Line
The Verizon outage highlights the critical importance of reliable cellular service for both daily communication and emergency situations. The incident underscores the need for robust network infrastructure and redundancy to minimize disruptions and ensure continuous connectivity. Businesses and individuals should consider diversifying their communication channels and having backup plans in place to mitigate the impact of potential outages.
Relevant Terms
SOS Mode: A state in which a mobile device cannot connect to its primary cellular network but can still make emergency calls.
Network Outage: A period during which a network is unavailable or experiences significant disruptions in service.
Microsoft, along with international law enforcement, disrupted the RedVDS cybercrime service, which enabled cybercriminals to conduct various attacks. The RedVDS infrastructure and associated domains were seized, hindering the platform's ability to facilitate fraud.
The Scheme
TTP 1: Providing access to disposable virtual computers for as little as $24 a month.
TTP 2: Facilitating phishing, BEC attacks, account takeovers, and fraud.
TTP 3: Pairing the service with GenAI tools to enhance attacks.
The Players
Threat Actor: Storm-2470
The Consequence
Outcome: Infrastructure seized and marketplace taken offline.
Assets Seized/Forfeited: $40 million in reported fraud losses since March 2025.
Strategic Takeaway
Disrupting cybercrime-as-a-service platforms like RedVDS is crucial to hinder large-scale cyberattacks and protect potential victims.
Relevant Terms
BEC (Business Email Compromise): A type of fraud where attackers gain access to email accounts to intercept communications and redirect payments.
Phishing: A type of online fraud where attackers send deceptive emails or messages to trick individuals into revealing sensitive information.