Related Threat Clusters
-
Critical wp2shell Vulnerability Enables Unauthenticated RCE in WordPress
A critical vulnerability chain, dubbed wp2shell, has been identified in WordPress Core, allowing unauthenticated attackers to execute arbitrary code on default installations. This vulnerability is tracked as…
78 articles · Updated July 20, 2026 -
DeepSeek AI Used in Autonomous Cyberattack Campaign by Chinese Threat Actor
A Chinese-speaking threat actor, identified as knaithe/KnYuan, executed an autonomous cyberattack campaign using DeepSeek AI and the Hermes Agent framework. The campaign targeted over 460 servers, attempting to exploit…
12 articles · Updated August 2, 2026 -
Critical Authentication Bypass Vulnerability in n8n (CVE-2026-21858)
A critical authentication bypass vulnerability has been identified in the n8n workflow automation platform, referenced as CVE-2026-21858. This flaw allows unauthorized access to workflows, potentially compromising…
1 article · Updated January 19, 2026 -
Critical Vulnerabilities in n8n Workflow Automation Platform Disclosed
Multiple critical vulnerabilities in the n8n open-source workflow automation platform were disclosed, allowing authenticated users to execute remote code on the server. These vulnerabilities, tracked as CVE-2026-25049,…
61 articles · Updated February 4, 2026 -
Malicious npm Packages Exploit n8n Workflow Automation Platform
Threat actors have targeted the n8n workflow automation platform by uploading malicious npm packages disguised as legitimate integrations. These packages lure developers into revealing their OAuth credentials,…
2 articles · Updated January 12, 2026 -
Critical Vulnerability CVE-2026-21858 Discovered in n8n Automation Tool
On January 7, 2026, a patch was released for CVE-2026-21858, a maximum severity vulnerability affecting n8n, a workflow automation application. This vulnerability could potentially allow unauthorized access and…
56 articles · Updated January 9, 2026 -
Critical Ni8mare Vulnerability in n8n Servers Exposes Thousands to Remote Code Execution
A critical vulnerability, tracked as CVE-2026-21858, has been discovered in the n8n workflow automation platform, allowing unauthenticated attackers to execute arbitrary commands and potentially take over an estimated…
3 articles · Updated January 8, 2026
Recent Intelligence Reports
- BleepingComputer summarised the finding — www.bleepingcomputer.com · August 2, 2026
- Unit 42 Ties DeepSeek Agent to 460+ Autonomous Hack Attempts — Aiweekly.Co · August 1, 2026
- DeepSeek Ran Autonomous Cyberattacks That Claude and OpenAI Safety Controls Blocked — Techtimes · August 1, 2026
- wp2shell: WordPress RCE (CVE-2026-63030) — Secra.Es · July 20, 2026
- Critical n8n flaws disclosed along with public exploits — Bleepingcomputer · February 4, 2026
- Vulnerability Workflow n8n | CVE-2026-21858 — Stormshield · January 19, 2026
- Malicious npm packages target the n8n automation platform in a supply chain attack — Csoonline · January 12, 2026
- CVE-2026-21858 — Arcticwolf · January 9, 2026