Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (4 February 2026)
Published: Loading…
At a Glance
- State-linked actors exploited Notepad++ update infrastructure between June and December 2025 to deliver malicious installers via WinGUp auto-updater.
- APT28 conducted Operation Neusploit exploiting Microsoft Office CVE-2026-21509 to deploy multi-stage malware including Outlook-stealing macros and persistent loaders.
- CVE-2025-40551 in SolarWinds Web Help Desk enables unauthenticated remote code execution, affecting versions up to 12.8.8 HF1 and permitting lateral movement.
- React Native Metro development server vulnerability CVE-2025-11953 has been actively exploited to deliver operational multi-stage malware to Windows and Linux machines.
- French prosecutors raided X offices in Paris investigating Grok AI sexual deepfakes, summoning Elon Musk and CEO Linda Yaccarino for voluntary interviews.
- French-hosted Kubernetes cluster performed 33,270 webhook scans targeting n8n platforms vulnerable to CVE-2026-21858, using coordinated ephemeral containers with consistent tooling.
Summary
Supply chain compromises continued with Notepad++, where state-linked actors exploited its update mechanism over six months, delivering malicious installers via WinGUp. The campaign persisted through stolen credentials even after hosting access was removed, and remediation included enforcing installer signature verification and relocating update services.
State-aligned operations targeted productivity software, as APT28 leveraged CVE-2026-21509 in Microsoft Office to execute Operation Neusploit. Multi-stage payloads included Outlook-stealing macros, steganographic loaders, and in-memory .NET implants, demonstrating persistent access techniques.
Critical vulnerabilities in enterprise management platforms were actively exploited, notably CVE-2025-40551 in SolarWinds Web Help Desk. The flaw permitted unauthenticated remote code execution, full system compromise, and lateral movement, prompting CISA’s KEV Catalog listing and mandated patching.
Development tools were also targeted, with React Native Metro server CVE-2025-11953 exploited in the wild to deliver malware to Windows and Linux environments. Exploitation involved repeated operational attacks rather than opportunistic scanning, emphasising persistent threat activity against dev infrastructures.
Abuse of AI and cloud platforms surfaced in legal and privacy contexts. French prosecutors raided X offices over Grok AI-generated sexual deepfakes, summoning executives for voluntary interviews. Investigations encompassed alleged child exploitation, illegal content dissemination, and platform operation violations.
Infrastructure reconnaissance campaigns included a French Kubernetes cluster conducting over 33,000 webhook scans targeting n8n workflow platforms vulnerable to CVE-2026-21858. Coordinated ephemeral containers were employed, indicating targeted probing of automation and integration services.
Highlights of the Day
Metro Development Server Exploited in Active Attacks
Researchers have observed real-world exploitation of CVE-2025-11953, a vulnerability in React Native’s Metro development server, with activity dating back to December 2025. Telemetry shows repeated, operational use to deliver multi-stage malware on exposed Windows systems, rather than isolated testing.
French Kubernetes Cluster Conducts Large-Scale Webhook Scans
GreyNoise researchers observed a French-hosted Kubernetes cluster performing 33,270 HTTP requests to probe webhook endpoints between 27 January and 3 February 2026. The campaign targeted file upload and document processing paths, including n8n workflow automation platforms vulnerable to CVE-2026-21858, using a coordinated, ephemeral container setup with consistent tooling across all nodes.
Notepad++ Details 2025 Supply Chain Compromise
Notepad++ disclosed that state-linked actors exploited its update infrastructure between June and December 2025, redirecting select update requests to deliver malicious installers. The attack leveraged weaknesses in the WinGUp auto-updater affecting versions 8.8.9 and earlier, and persisted through stolen credentials even after hosting access was removed. Remediation included mandatory installer signature verification, tightened update controls, and migration from the compromised hosting environment.
Critical Remote Code Execution Found in SolarWinds Web Help Desk
A critical unpatched vulnerability (CVE-2025-40551) in SolarWinds Web Help Desk allows unauthenticated attackers to execute arbitrary commands. The flaw has been exploited in the wild, prompting CISA to add it to the KEV Catalog and mandate remediation for federal agencies. Affected versions up to 12.8.8 HF1 are addressed in version 2026.1, with the vulnerability enabling full system compromise and potential lateral movement in poorly segmented environments.
APT28 Exploits Office Flaw in Neusploit Campaign
Zscaler researchers detailed Operation Neusploit, a campaign in which APT28 exploited CVE-2026-21509 via weaponised RTF files to deploy malware. The activity used multiple attack chains to steal emails through malicious Outlook macros or establish persistent access using loaders, steganography, and in-memory .NET implants. The operation demonstrates continued use of sophisticated, multi-stage techniques linked to the APT28 threat actor.
French Prosecutors Raid X Over Grok AI Deepfakes
French authorities raided X’s Paris offices as part of a criminal investigation into the Grok AI tool, linked to sexually explicit deepfakes and Holocaust-denial content. Elon Musk and CEO Linda Yaccarino have been summoned for interviews, while additional employees are scheduled to be questioned as witnesses. The probe examines multiple alleged offences, including child exploitation, illegal content dissemination, data fraud, and unlawful platform operations.
Daily Coverage