CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (4 February 2026)

Published: Loading…

At a Glance

  • State-linked actors exploited Notepad++ update infrastructure between June and December 2025 to deliver malicious installers via WinGUp auto-updater.
  • APT28 conducted Operation Neusploit exploiting Microsoft Office CVE-2026-21509 to deploy multi-stage malware including Outlook-stealing macros and persistent loaders.
  • CVE-2025-40551 in SolarWinds Web Help Desk enables unauthenticated remote code execution, affecting versions up to 12.8.8 HF1 and permitting lateral movement.
  • React Native Metro development server vulnerability CVE-2025-11953 has been actively exploited to deliver operational multi-stage malware to Windows and Linux machines.
  • French prosecutors raided X offices in Paris investigating Grok AI sexual deepfakes, summoning Elon Musk and CEO Linda Yaccarino for voluntary interviews.
  • French-hosted Kubernetes cluster performed 33,270 webhook scans targeting n8n platforms vulnerable to CVE-2026-21858, using coordinated ephemeral containers with consistent tooling.

Summary

Supply chain compromises continued with Notepad++, where state-linked actors exploited its update mechanism over six months, delivering malicious installers via WinGUp. The campaign persisted through stolen credentials even after hosting access was removed, and remediation included enforcing installer signature verification and relocating update services.

State-aligned operations targeted productivity software, as APT28 leveraged CVE-2026-21509 in Microsoft Office to execute Operation Neusploit. Multi-stage payloads included Outlook-stealing macros, steganographic loaders, and in-memory .NET implants, demonstrating persistent access techniques.

Critical vulnerabilities in enterprise management platforms were actively exploited, notably CVE-2025-40551 in SolarWinds Web Help Desk. The flaw permitted unauthenticated remote code execution, full system compromise, and lateral movement, prompting CISA’s KEV Catalog listing and mandated patching.

Development tools were also targeted, with React Native Metro server CVE-2025-11953 exploited in the wild to deliver malware to Windows and Linux environments. Exploitation involved repeated operational attacks rather than opportunistic scanning, emphasising persistent threat activity against dev infrastructures.

Abuse of AI and cloud platforms surfaced in legal and privacy contexts. French prosecutors raided X offices over Grok AI-generated sexual deepfakes, summoning executives for voluntary interviews. Investigations encompassed alleged child exploitation, illegal content dissemination, and platform operation violations.

Infrastructure reconnaissance campaigns included a French Kubernetes cluster conducting over 33,000 webhook scans targeting n8n workflow platforms vulnerable to CVE-2026-21858. Coordinated ephemeral containers were employed, indicating targeted probing of automation and integration services.

Highlights of the Day

Metro Development Server Exploited in Active Attacks

Researchers have observed real-world exploitation of CVE-2025-11953, a vulnerability in React Native’s Metro development server, with activity dating back to December 2025. Telemetry shows repeated, operational use to deliver multi-stage malware on exposed Windows systems, rather than isolated testing.

Source: VulnCheck

French Kubernetes Cluster Conducts Large-Scale Webhook Scans

GreyNoise researchers observed a French-hosted Kubernetes cluster performing 33,270 HTTP requests to probe webhook endpoints between 27 January and 3 February 2026. The campaign targeted file upload and document processing paths, including n8n workflow automation platforms vulnerable to CVE-2026-21858, using a coordinated, ephemeral container setup with consistent tooling across all nodes.

Notepad++ Details 2025 Supply Chain Compromise

Notepad++ disclosed that state-linked actors exploited its update infrastructure between June and December 2025, redirecting select update requests to deliver malicious installers. The attack leveraged weaknesses in the WinGUp auto-updater affecting versions 8.8.9 and earlier, and persisted through stolen credentials even after hosting access was removed. Remediation included mandatory installer signature verification, tightened update controls, and migration from the compromised hosting environment.

Critical Remote Code Execution Found in SolarWinds Web Help Desk

A critical unpatched vulnerability (CVE-2025-40551) in SolarWinds Web Help Desk allows unauthenticated attackers to execute arbitrary commands. The flaw has been exploited in the wild, prompting CISA to add it to the KEV Catalog and mandate remediation for federal agencies. Affected versions up to 12.8.8 HF1 are addressed in version 2026.1, with the vulnerability enabling full system compromise and potential lateral movement in poorly segmented environments.

Source: Bitsight

APT28 Exploits Office Flaw in Neusploit Campaign

Zscaler researchers detailed Operation Neusploit, a campaign in which APT28 exploited CVE-2026-21509 via weaponised RTF files to deploy malware. The activity used multiple attack chains to steal emails through malicious Outlook macros or establish persistent access using loaders, steganography, and in-memory .NET implants. The operation demonstrates continued use of sophisticated, multi-stage techniques linked to the APT28 threat actor.

French Prosecutors Raid X Over Grok AI Deepfakes

French authorities raided X’s Paris offices as part of a criminal investigation into the Grok AI tool, linked to sexually explicit deepfakes and Holocaust-denial content. Elon Musk and CEO Linda Yaccarino have been summoned for interviews, while additional employees are scheduled to be questioned as witnesses. The probe examines multiple alleged offences, including child exploitation, illegal content dissemination, data fraud, and unlawful platform operations.

Daily Coverage

Developments
Notepad++ BreachApt28 NeusploitSolarwinds RceMetro4Shell Exploitation
Vulnerabilities
CVE-2025-40551Web Help Desk 12.8.8 Hf1 And Below (Critical)CVE-2025-8088Winrar 7.13 (High)CVE-2026-21509Microsoft Office 2019 19.0.0 (High)CVE-2026-21858N8N < 1.121.0 (Critical)CVE-2025-11953The Metro Development Server, Which Is Opened By The React Native Community Cli, Binds To External Interfaces By Default. The Server Exposes An Endpoint That Is Vulnerable To Os Command Injection. This Allows Unauthenticated Network Attackers To Send A Post Request To The Server And Run Arbitrary Executables. On Windows, The Attackers Can Also Execute Arbitrary Shell Commands With Fully Controlled Arguments.CVE-2025-33201Triton Inference Server All Versions Prior To R25.10 (High)CVE-2026-24149Megatron-Lm (High)
Threat Groups
APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.Transparent Tribe[Also known as: APT36] Transparent Tribe is a suspected Pakistanbased threat group that has been active since at least 2013, primarily targeting diplomatic, defense, and research organizations in India and Afghanistan.AkiraAkira is a ransomware variant and ransomware deployment entity active since at least March 2023. Akira uses compromised credentials to access singlefactor external access mechanisms such as VPNs for initial access, then various publiclyavailable tools and techniques for lateral movement. Akira operations are associated with "double extortion" ransomware activity, where data is exfiltrated from victim environments prior to encryption, with threats to publish files if a ransom is not paid. Technical analysis of Akira ransomware indicates variants capable of targeting Windows or VMWare ESXi hypervisors and multiple overlaps with Conti ransomware.APT41APT41 is a threat group that researchers have assessed as Chinese statesponsored espionage group that also conducts financiallymotivated operations. Active since at least 2012, APT41 has been observed targeting various industries, including but not limited to healthcare, telecom, technology, finance, education, retail and video game industries in 14 countries. Notable behaviors include using a wide range of malware and tools to complete mission objectives. APT41 overlaps at least partially with public reporting on groups including BARIUM and Winnti Group.