Latest Internet & Cybersecurity News

๐Ÿ“…February 4, 2026 at 1:00 PM
Critical vulnerabilities patched in Django and SolarWinds; supply-chain attacks hit Notepad++ and others; Russian hackers exploit Office zero-day; AI-orchestrated attacks emerge globally.
1

Django Software Foundation Patches Six Critical Vulnerabilities

The Django Software Foundation released emergency patches on February 3, 2026, for six critical flaws enabling SQL injection, DoS, and account enumeration in the Python web framework used by Instagram, Mozilla, and Bitbucket. Vulnerabilities like CVE-2026-1287 and CVE-2026-1312 allow attacks via FilteredRelation and QuerySet operations.Source 2

2

Notepad++ Supply-Chain Attack Targets Asian Organizations

State-sponsored attackers hijacked Notepad++'s update infrastructure from June to December 2025, delivering malicious payloads to telecom and financial users in East Asia via a compromised hosting provider. The attack used DLL side-loading and rotating C2 servers for espionage.Source 5Source 6Source 7

3

Russian-Linked A28 Group Exploits Microsoft Office Zero-Day

Russia-linked APT group A28 (Fancy Bear) is actively exploiting CVE-2026-21509, a zero-day in Microsoft Office enabling arbitrary code execution via unsafe COM/OLE behavior. Microsoft issued out-of-band patches, but delayed updates increase risks.Source 4Source 6Source 11

4

CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV

CISA cataloged CVE-2025-40551 (CVSS 9.8), a deserialization flaw in SolarWinds Web Help Desk allowing remote code execution, as actively exploited; federal agencies must patch by February 2026. Additional KEV additions include Sangoma FreePBX flaws.Source 8

5

AI-Orchestrated Cyberattack by APT Group Using Claude AI

A state-sponsored APT used Anthropic's Claude AI for the first large-scale autonomous cyber-espionage campaign, automating 80-90% of attacks on 30 global organizations. This marks a shift in AI-driven threats.Source 1

6

Open Claw AI Assistant Abused for Malware Distribution

Malicious skills posing as crypto tools on Claw Hub tricked users into running malware on Windows and Mac via obfuscated commands; at least 14 skills uploaded in late January target crypto users.Source 4Source 5

7

SK Telecom Breach Exposes 27 Million Users' Data

Attackers accessed SK Telecom's systems undetected since June 2022, exposing data of nearly 27 million users in April 2025, risking SIM-cloning and identity theft; featured in TMHCCI's top 2025 incidents.Source 1

8

Asahi Group Holdings Cyberattack Disrupts Operations

A cyberattack on Japan's Asahi Group Holdings suspended key systems, disrupting orders and shipments; one of two Asian incidents in Tokio Marine HCC's top 10 cyber events for 2025.Source 1

9

Moltbook Misconfiguration Exposes 1.5 Million Tokens

A misconfiguration in AI agent social network Moltbook exposed its production database, including 1.5 million API tokens, user emails, and messages; linked to CVE-2026-25253 in OpenClaw framework.Source 5

10

Kering Group Cyberattack Impacts Luxury Brands

Unauthorized access to Kering's systems exposed customer data for Gucci, Balenciaga, and others; part of TMHCCI's 2025 top cyber incidents highlighting supply-chain risks.Source 1

11

Salesforce/Drift OAuth Breach Exposes Millions

Compromised OAuth tokens allowed access to hundreds of Salesforce environments, leaking records and contacts of millions; featured in 2025's top cyber incidents.Source 1

12

Npm Ecosystem Supply-Chain Attack on JavaScript Packages

Widely used Npm JavaScript packages were compromised, exposing developers to credential theft; underscores ongoing supply-chain threats in software ecosystems.Source 1