Multiple critical vulnerabilities were disclosed and exploited across widely deployed infrastructure software, including D-Link DSL routers, Veeam Backup & Replication, and n8n workflow automation platforms. Several flaws enabled unauthenticated or low-privilege remote code execution with CVSS scores ranging from 9.0 to 10.0.
Exploitation of unsupported or legacy network devices intensified, with attackers abusing zero-day command injection flaws in discontinued D-Link hardware. Similar device-level weaknesses were reported in Totolink range extenders, allowing full device takeover through firmware handling errors.
Supply chain and software ecosystem risks persisted as npm announced staged publishing controls following the Shai-Hulud campaign. A critical flaw in the jsPDF JavaScript library enabled attackers to exfiltrate local filesystem data through crafted PDF generation.
Extortion and data theft incidents affected telecommunications and public sector organisations, including Brightspeed, European Space Agency, and Illinois Department of Human Services. Exposed datasets included extensive personally identifiable information and internal records.
Phishing and malware delivery campaigns targeted specific industries and regions using tailored lures. Fake Booking.com emails delivered DCRat malware to hospitality staff, while misconfigured email routing enabled internal domain spoofing leveraged by phishing-as-a-service platforms.
Botnet and credential-based attacks expanded against poorly secured servers and cloud environments. The GoBruteforcer botnet exploited weak defaults on Linux servers, while threat actor Zestix breached around 50 enterprises lacking multi-factor authentication.
Veeam has released updates for Backup & Replication addressing four vulnerabilities, including a critical remote code execution flaw tracked as CVE-2025-59470. The issues affect version 13 builds prior to 13.0.1.1071 and could allow highly privileged users to execute code as system-level accounts through crafted parameters or configuration files.
The workflow automation platform n8n has disclosed a maximum-severity remote code execution flaw that allows authenticated users to run untrusted code and fully compromise affected instances. Tracked as CVE-2026-21877, the issue affects both self-hosted deployments and n8n Cloud versions prior to 1.121.3, where it has been resolved.
US broadband provider Brightspeed is investigating claims by the Crimson Collective extortion group that data from more than one million residential customers was stolen. The alleged dataset includes extensive personal, account, billing and payment information, with a limited sample shared publicly by the group while the company continues its investigation.
Check Point Research has detailed a renewed GoBruteforcer botnet campaign targeting internet-exposed Linux servers using weak and reused credentials across FTP, database services and phpMyAdmin. The activity is linked to widespread reuse of default configurations, including those generated by AI tools and legacy server stacks, and includes financially motivated attacks against cryptocurrency and blockchain projects.
Huntress has documented active exploitation of VMware ESXi hypervisors using a sophisticated virtual machine escape toolkit observed during a real-world intrusion. The attack chain combined compromised VPN access, guest-to-host escape techniques and previously disclosed ESXi vulnerabilities to gain control of the hypervisor and deploy a stealthy backdoor.