Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
n8n patched a high-severity expression-sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m, CVSS 8.7) that lets authenticated workflow editors execute OS commands on the n8n server. Security Joes discovered the flaw while probing n8n's February fix for CVE-2026-27577 for bypasses.
Cyble's analysis of the global threat landscape in H1 2026 reveals 261 distinct threat actor profiles operating simultaneously. Nation-state APT groups are the largest category at 45.2%, followed by ransomware operators at 28.7%, highlighting the dominance of state-sponsored cyber threats.
Cyble's analysis of the global threat landscape in H1 2026 reveals 261 distinct threat actor profiles operating simultaneously. Nation-state APT groups are the largest category at 45.2%, followed by ransomware operators at 28.7%, highlighting the dominance of state-sponsored cyber threats.
Cyble's H1 2026 threat landscape analysis reveals that Advanced Persistent Threats (APTs) dominate activity, with ransomware, data breaches, and hacktivism highlighting the industrialization of cybercrime.
You may have heard your peers say, “Cybercrime has become industrialized.” But did you have any proof? We do.
Operation BlueDash is a Microsoft Teams-themed phishing campaign that delivers legitimate remote monitoring and management (RMM) tools including Level RMM and ConnectWise ScreenConnect. Victims are directed through compromised web infrastructure to a fake Microsoft Store page claiming Teams needs updating, which drops an Inno Setup loader that fetches and installs the RMM tools using attacker-controlled enrollment secrets for persistent remote access.