Infosecurity Magazine reports that open-source automation platform n8n has been impacted by a pair of maximum severity sandbox escape flaws that could enable total server takeover and credential compromise.
BleepingComputer reports that the high-severity VMware ESXi sandbox escape issue, tracked as CVE-2025-22225, was confirmed by the Cybersecurity and Infrastructure Security Agency to have been harnessed in ransomware attacks nearly a year after the flaw was added to the agency's Known Exploited Vulnerabilities catalog.
Intrusions exploiting the WinRAR path traversal flaw, tracked as CVE-2025-8088, have been launched by newly emergent threat operation Amaranth Dragon, which is associated with Chinese state-backed hacking group APT41, against Southeast Asian government and law enforcement agencies since August, BleepingComputer reports.
Moves by the Cybersecurity and Infrastructure Security Agency to update ransomware-related exploitation on dozens of software vulnerabilities last year without alerting defenders were noted by GreyNoise Senior Director of Security Research and Detection Engineering Glenn Thorpe to have potentially resulted in overlooked ransomware intrusions, reports The Register.
Cybernews reports that more than 8.7 billion Chinese records have been spilled by an unprotected Elasticsearch cluster in what is among the largest exposures in the open-source distributed search and analytics engine.
Multiple threat actors were observed by watchTowr Labs to have harnessed a pair of critical Ivanti Endpoint Manager Mobile code injection vulnerabilities, tracked as CVE-2026-1281 and CVE-2026-1340, in global attacks even as Ivanti dismissed an exploit chain involving both flaws, according to CyberScoop.
Intrusions leveraging the critical React Native Community CLI NPM package vulnerability, tracked as CVE-2025-11953, have been launched to compromise Windows and Linux systems with malware since late December, reports SecurityWeek.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.