<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>UINAT — Information Security Hub</title><description>Breaking infosec news, breach reports, company rankings, and expert guides.</description><link>https://uinat.com/</link><item><title>Operation Cronos: How Law Enforcement Dismantled LockBit, the World&apos;s Largest Ransomware Operation</title><link>https://uinat.com/news/lockbit-operation-cronos-takedown-2024/</link><guid isPermaLink="true">https://uinat.com/news/lockbit-operation-cronos-takedown-2024/</guid><description>On February 20, 2024, a 10-country task force seized LockBit&apos;s infrastructure, identified 194 affiliates, and froze $112 million in cryptocurrency in the most significant ransomware takedown in history.</description><pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Cryptography and Key Management: Enterprise Implementation Guide</title><link>https://uinat.com/guides/cryptography-key-management-guide/</link><guid isPermaLink="true">https://uinat.com/guides/cryptography-key-management-guide/</guid><description>A practical guide to implementing enterprise cryptography and key management, covering algorithm selection, HSMs, PKI, secrets management, and post-quantum cryptography transition.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate></item><item><title>DNS Security: Enterprise Implementation Guide</title><link>https://uinat.com/guides/dns-security-implementation/</link><guid isPermaLink="true">https://uinat.com/guides/dns-security-implementation/</guid><description>A practical guide to implementing DNS security, covering protective DNS, DNSSEC, encrypted DNS protocols, threat detection, and enterprise architecture patterns.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Mobile Security and BYOD: Enterprise Implementation Guide</title><link>https://uinat.com/guides/mobile-security-byod-guide/</link><guid isPermaLink="true">https://uinat.com/guides/mobile-security-byod-guide/</guid><description>A practical guide to implementing mobile security and BYOD programs, covering MDM deployment, containerization, app vetting, conditional access, and compliance requirements for iOS and Android.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Security Program Development: Building from Scratch</title><link>https://uinat.com/guides/security-program-development/</link><guid isPermaLink="true">https://uinat.com/guides/security-program-development/</guid><description>A practical guide for new CISOs and security leaders building security programs from scratch, covering governance, risk assessment, team building, framework selection, and executive communication.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Top Database Security Platforms for 2026</title><link>https://uinat.com/rankings/top-database-security-platforms-2026/</link><guid isPermaLink="true">https://uinat.com/rankings/top-database-security-platforms-2026/</guid><description>Ranking the leading database security solutions based on activity monitoring, encryption, access controls, cloud database coverage, and compliance automation.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Top Enterprise Password Managers for 2026</title><link>https://uinat.com/rankings/top-enterprise-password-managers-2026/</link><guid isPermaLink="true">https://uinat.com/rankings/top-enterprise-password-managers-2026/</guid><description>Ranking the leading enterprise password management solutions based on security architecture, SSO integration, admin controls, compliance certifications, and enterprise scalability.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Top Mobile Threat Defense Platforms for 2026</title><link>https://uinat.com/rankings/top-mtd-platforms-2026/</link><guid isPermaLink="true">https://uinat.com/rankings/top-mtd-platforms-2026/</guid><description>Ranking the leading mobile threat defense solutions based on on-device detection, phishing protection, app vetting, network security, and enterprise integration capabilities.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Top Privacy Management Platforms for 2026</title><link>https://uinat.com/rankings/top-privacy-management-platforms-2026/</link><guid isPermaLink="true">https://uinat.com/rankings/top-privacy-management-platforms-2026/</guid><description>Ranking the leading privacy management solutions based on consent management, DSAR automation, data mapping, regulatory coverage, and integration capabilities.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Australia Essential Eight: ACSC Cybersecurity Mitigation Strategies</title><link>https://uinat.com/compliance/australia-essential-eight/</link><guid isPermaLink="true">https://uinat.com/compliance/australia-essential-eight/</guid><description>The Essential Eight is a set of baseline cybersecurity mitigation strategies from the Australian Cyber Security Centre (ACSC) designed to protect organizations against cyber threats. Updated July 2024 with refined maturity levels.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate></item><item><title>GLBA Compliance: Gramm-Leach-Bliley Act Requirements for Financial Institutions</title><link>https://uinat.com/compliance/glba-compliance-guide/</link><guid isPermaLink="true">https://uinat.com/compliance/glba-compliance-guide/</guid><description>The Gramm-Leach-Bliley Act requires financial institutions to protect customer information through the Privacy Rule, Safeguards Rule, and Pretexting provisions. Major Safeguards Rule updates effective 2023-2024 mandate enhanced cybersecurity controls.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate></item><item><title>SOX IT Controls: Section 404 Compliance for IT General Controls and Application Controls</title><link>https://uinat.com/compliance/sox-it-controls-guide/</link><guid isPermaLink="true">https://uinat.com/compliance/sox-it-controls-guide/</guid><description>Sarbanes-Oxley Section 404 requires publicly traded companies to establish, document, and test internal controls over financial reporting, including IT General Controls and application controls supporting financial systems.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Clop Exploits Oracle E-Business Suite Zero-Days in Massive Extortion Campaign</title><link>https://uinat.com/news/clop-oracle-ebs-zero-day-campaign-2026/</link><guid isPermaLink="true">https://uinat.com/news/clop-oracle-ebs-zero-day-campaign-2026/</guid><description>The Clop ransomware group weaponized CVE-2025-61882 and CVE-2025-61884 to breach nearly 100 organizations including Allianz UK, GlobalLogic, Envoy Air, Harvard, and Washington Post, with ransom demands reaching $50 million.</description><pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Coupang Data Breach Expands: 33.7 Million Accounts Compromised, 165,000 Additional Users Affected</title><link>https://uinat.com/news/coupang-data-breach-33-million-accounts-2026/</link><guid isPermaLink="true">https://uinat.com/news/coupang-data-breach-33-million-accounts-2026/</guid><description>South Korean e-commerce giant Coupang confirmed an additional 165,000 user accounts were exposed in the massive data breach affecting 33.7 million total accounts, triggered by a former employee using valid authentication keys.</description><pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate></item><item><title>China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Southeast Asian Espionage Campaigns</title><link>https://uinat.com/news/amaranth-dragon-apt41-winrar-exploitation-2026/</link><guid isPermaLink="true">https://uinat.com/news/amaranth-dragon-apt41-winrar-exploitation-2026/</guid><description>Check Point Research documents a new threat cluster weaponizing CVE-2025-8088 within days of disclosure to target government and law enforcement agencies across Cambodia, Thailand, Philippines, and neighboring countries.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>DEAD#VAX Campaign Uses IPFS-Hosted VHD Files to Deploy AsyncRAT via Fileless Execution</title><link>https://uinat.com/news/dead-vax-asyncrat-ipfs-campaign-2026/</link><guid isPermaLink="true">https://uinat.com/news/dead-vax-asyncrat-ipfs-campaign-2026/</guid><description>Securonix researchers document a sophisticated malware campaign that chains IPFS hosting, virtual hard disk abuse, and in-memory shellcode injection to deliver AsyncRAT while evading traditional detection.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Metro4Shell: Critical React Native CLI Vulnerability Actively Exploited Against Developers</title><link>https://uinat.com/news/metro4shell-react-native-rce-exploitation-2026/</link><guid isPermaLink="true">https://uinat.com/news/metro4shell-react-native-rce-exploitation-2026/</guid><description>CVE-2025-11953 in React Native CLI&apos;s Metro Development Server is being exploited in the wild to deploy Rust-based malware on developer systems, with attacks observed since December 2025.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>APT28 Deploys LAMEHUG: First Known Malware Using LLMs in Live Operations</title><link>https://uinat.com/news/apt28-lamehug-ai-malware-ukraine-2026/</link><guid isPermaLink="true">https://uinat.com/news/apt28-lamehug-ai-malware-ukraine-2026/</guid><description>Russia&apos;s APT28 has deployed LAMEHUG and PROMPTSTEAL malware that queries large language models via Hugging Face to dynamically generate attack commands, marking the first confirmed use of AI-powered malware in active cyber operations.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>ShinyHunters Publishes Harvard and UPenn Data: 2 Million Records Exposed</title><link>https://uinat.com/news/harvard-upenn-shinyhunters-breach-2026/</link><guid isPermaLink="true">https://uinat.com/news/harvard-upenn-shinyhunters-breach-2026/</guid><description>The ShinyHunters cybercriminal group published stolen data from Harvard University and the University of Pennsylvania after ransom demands went unpaid, exposing over 2 million alumni, donor, and student records.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>New n8n Vulnerability CVE-2026-25049 Bypasses Previous Patch to Enable Remote Code Execution</title><link>https://uinat.com/news/n8n-cve-2026-25049-sandbox-bypass-rce-2026/</link><guid isPermaLink="true">https://uinat.com/news/n8n-cve-2026-25049-sandbox-bypass-rce-2026/</guid><description>A critical flaw in n8n (CVSS 9.4) exploits TypeScript/JavaScript type mismatch to bypass sanitization from a December 2025 patch, enabling authenticated remote command execution via webhook workflows.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>React2Shell Exploitation Enables Massive NGINX Web Traffic Hijacking Campaign</title><link>https://uinat.com/news/react2shell-nginx-traffic-hijacking-campaign-2026/</link><guid isPermaLink="true">https://uinat.com/news/react2shell-nginx-traffic-hijacking-campaign-2026/</guid><description>Threat actors are using CVE-2025-55182 exploitation to inject malicious NGINX configurations that silently redirect web traffic through attacker infrastructure, targeting Asian TLDs and government sites.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>ICS/OT Security Fundamentals: Protecting Industrial Control Systems</title><link>https://uinat.com/guides/ics-ot-security-fundamentals/</link><guid isPermaLink="true">https://uinat.com/guides/ics-ot-security-fundamentals/</guid><description>A comprehensive guide to securing Industrial Control Systems and Operational Technology, covering the Purdue Model, ICS-specific threats, network segmentation, and building an OT security program.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Building an Insider Threat Detection and Prevention Program</title><link>https://uinat.com/guides/insider-threat-program/</link><guid isPermaLink="true">https://uinat.com/guides/insider-threat-program/</guid><description>A comprehensive guide to establishing an insider threat program, covering detection technologies, behavioral indicators, HR integration, legal considerations, and balancing security with employee trust.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Privileged Access Management: Implementation Guide</title><link>https://uinat.com/guides/privileged-access-management-implementation/</link><guid isPermaLink="true">https://uinat.com/guides/privileged-access-management-implementation/</guid><description>A practical guide to implementing PAM, covering credential vaulting, just-in-time access, session recording, service account management, and cloud privileged access across AWS, Azure, and GCP.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Building an Effective Security Awareness Training Program</title><link>https://uinat.com/guides/security-awareness-training-program/</link><guid isPermaLink="true">https://uinat.com/guides/security-awareness-training-program/</guid><description>A comprehensive guide to developing security awareness training that changes behavior, not just checks compliance boxes. Covers program design, phishing simulations, metrics, and building a security culture.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Security Metrics and Board Reporting: A CISO&apos;s Guide</title><link>https://uinat.com/guides/security-metrics-board-reporting/</link><guid isPermaLink="true">https://uinat.com/guides/security-metrics-board-reporting/</guid><description>A practical guide to developing security metrics that matter, communicating cyber risk to boards in financial terms, and building dashboards that drive decisions rather than just display data.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>SIEM and Log Management: Implementation Best Practices</title><link>https://uinat.com/guides/siem-log-management-implementation/</link><guid isPermaLink="true">https://uinat.com/guides/siem-log-management-implementation/</guid><description>A comprehensive guide to implementing SIEM, covering log source prioritization, detection engineering, architecture patterns, cost optimization, and the shift toward data lake architectures.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>APT28 Exploits Microsoft Office Zero-Day in Operation Neusploit Targeting Ukraine</title><link>https://uinat.com/news/apt28-operation-neusploit-office-zero-day-2026/</link><guid isPermaLink="true">https://uinat.com/news/apt28-operation-neusploit-office-zero-day-2026/</guid><description>Russia&apos;s APT28 weaponized CVE-2026-21509 within three days of Microsoft&apos;s disclosure, deploying MiniDoor email stealers and PixyNetLoader against Ukraine, Slovakia, and Romania.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Mozilla Adds One-Click Option to Disable All AI Features in Firefox</title><link>https://uinat.com/news/mozilla-firefox-ai-disable-option-2026/</link><guid isPermaLink="true">https://uinat.com/news/mozilla-firefox-ai-disable-option-2026/</guid><description>Firefox 148 introduces a &apos;Block AI enhancements&apos; toggle that disables all current and future generative AI features, plus individual controls for translations, tab grouping, link previews, and chatbot access.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>DockerDash Vulnerability in Ask Gordon AI Enables Code Execution via Image Metadata</title><link>https://uinat.com/news/dockerdash-ai-assistant-vulnerability-2026/</link><guid isPermaLink="true">https://uinat.com/news/dockerdash-ai-assistant-vulnerability-2026/</guid><description>Noma Labs discovered a critical flaw in Docker&apos;s Ask Gordon AI assistant allowing attackers to hijack AI reasoning through malicious image metadata, leading to remote code execution or data exfiltration.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Moltbook AI Social Network Database Exposure</title><link>https://uinat.com/breaches/moltbook-database-exposure-2026/</link><guid isPermaLink="true">https://uinat.com/breaches/moltbook-database-exposure-2026/</guid><description>A misconfigured Supabase database at Moltbook, the &apos;social network for AI agents,&apos; exposed 1.5 million API tokens, 35,000 email addresses, and private messages—revealing the platform was mostly humans operating bot fleets.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Ascension Health — Black Basta Ransomware Disrupts 100+ Hospitals</title><link>https://uinat.com/breaches/ascension-health-ransomware-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/ascension-health-ransomware-2024/</guid><description>A Black Basta ransomware attack on Ascension Health, one of the largest US Catholic healthcare systems, forced hospitals to divert emergency patients, delay surgeries, and revert to paper records, affecting 5.6 million patients.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Evolve Bank &amp; Trust — LockBit Ransomware Exposes 7.6 Million via Fintech Partners</title><link>https://uinat.com/breaches/evolve-bank-lockbit-ransomware-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/evolve-bank-lockbit-ransomware-2024/</guid><description>A LockBit ransomware attack on Evolve Bank &amp; Trust, a banking-as-a-service provider for major fintechs, exposed data of 7.6 million individuals and rippled through partners including Affirm, Mercury, Wise, and others.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Hot Topic — 57 Million Customer Records Exposed in Snowflake Credential Breach</title><link>https://uinat.com/breaches/hot-topic-snowflake-breach-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/hot-topic-snowflake-breach-2024/</guid><description>One of the largest retail data breaches in history exposed 57 million Hot Topic, Torrid, and BoxLunch customer records including 25 million credit card numbers after attackers compromised Snowflake cloud credentials stolen via infostealer malware.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Kaiser Foundation Health Plan — 13.4 Million Members Exposed via Web Tracking</title><link>https://uinat.com/breaches/kaiser-foundation-data-exposure-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/kaiser-foundation-data-exposure-2024/</guid><description>Kaiser Foundation Health Plan disclosed that web tracking technologies including Google Analytics shared personal health information of 13.4 million current and former members with third-party advertisers, the second-largest healthcare breach of 2024.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>MoneyGram — Social Engineering Attack Causes Global Service Outage</title><link>https://uinat.com/breaches/moneygram-social-engineering-2024/</link><guid isPermaLink="true">https://uinat.com/breaches/moneygram-social-engineering-2024/</guid><description>A social engineering attack targeting MoneyGram&apos;s IT helpdesk led to a week-long global outage affecting billions in remittances and exposed sensitive customer data including government IDs and bank account information.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>SK Telecom — 25 Million Subscribers Exposed in South Korea&apos;s Worst Telecom Breach</title><link>https://uinat.com/breaches/sk-telecom-usim-breach-2025/</link><guid isPermaLink="true">https://uinat.com/breaches/sk-telecom-usim-breach-2025/</guid><description>A sophisticated malware attack on South Korea&apos;s largest mobile carrier compromised USIM authentication data for nearly the entire subscriber base, forcing mass SIM replacements and costing over $120 million.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Network Security Fundamentals: A Practical Guide</title><link>https://uinat.com/guides/network-security-fundamentals/</link><guid isPermaLink="true">https://uinat.com/guides/network-security-fundamentals/</guid><description>Comprehensive guide to network security covering defense in depth, segmentation, firewalls, IDS/IPS, zero trust architecture, and protection against common network attacks including lateral movement and man-in-the-middle.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Top Identity Threat Detection and Response (ITDR) Platforms 2026</title><link>https://uinat.com/rankings/top-itdr-platforms-2026/</link><guid isPermaLink="true">https://uinat.com/rankings/top-itdr-platforms-2026/</guid><description>Ranking the leading ITDR platforms for detecting and responding to identity-based attacks including credential theft, privilege escalation, and Active Directory compromise.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Top Security Awareness Training Platforms 2026</title><link>https://uinat.com/rankings/top-security-awareness-training-2026/</link><guid isPermaLink="true">https://uinat.com/rankings/top-security-awareness-training-2026/</guid><description>Ranking the leading security awareness training and human risk management platforms based on content quality, phishing simulation, behavioral analytics, and effectiveness at reducing human risk.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>NationStates Browser Game Confirms Data Breach After RCE Exploit</title><link>https://uinat.com/news/nationstates-data-breach-rce-user-data-exposed/</link><guid isPermaLink="true">https://uinat.com/news/nationstates-data-breach-rce-user-data-exposed/</guid><description>NationStates shut down its site after a vulnerability reporter chained input sanitization flaws to achieve remote code execution, copying user emails, password hashes, and IP addresses.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Notepad++ Update Mechanism Hijacked by Chinese Threat Actors to Deliver Malware</title><link>https://uinat.com/news/notepad-supply-chain-attack-chinese-threat-actors/</link><guid isPermaLink="true">https://uinat.com/news/notepad-supply-chain-attack-chinese-threat-actors/</guid><description>Lotus Blossom APT compromised Notepad++&apos;s hosting provider to intercept update traffic and deliver the Chrysalis backdoor to targeted government and financial organizations over a six-month period.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Critical vLLM Vulnerability Lets Attackers Hijack AI Servers via Video Link</title><link>https://uinat.com/news/vllm-critical-rce-vulnerability-2026/</link><guid isPermaLink="true">https://uinat.com/news/vllm-critical-rce-vulnerability-2026/</guid><description>CVE-2026-22778, a critical RCE in vLLM versions 0.8.3-0.14.0, chains a PIL information leak with a JPEG2000 heap overflow to achieve code execution through a malicious video link.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>OpenClaw AI Agent Vulnerability Enables One-Click Remote Code Execution</title><link>https://uinat.com/news/openclaw-one-click-rce-vulnerability-2026/</link><guid isPermaLink="true">https://uinat.com/news/openclaw-one-click-rce-vulnerability-2026/</guid><description>CVE-2026-25253 (CVSS 8.8) allows attackers to steal authentication tokens and achieve RCE through a single malicious link via cross-site WebSocket hijacking—even on localhost-only OpenClaw instances.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>400+ Malicious OpenClaw Skills Flood ClawHub With Info-Stealing Malware</title><link>https://uinat.com/news/malicious-openclaw-skills-clawhub-malware-2026/</link><guid isPermaLink="true">https://uinat.com/news/malicious-openclaw-skills-clawhub-malware-2026/</guid><description>Over 400 malicious OpenClaw AI agent skills on ClawHub deploy Atomic Stealer via ClickFix-style social engineering. The hightower6eu account alone published 314 malicious skills targeting crypto and developer credentials.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Microsoft Announces Three-Phase Plan to Disable NTLM by Default</title><link>https://uinat.com/news/microsoft-ntlm-deprecation-three-phase-plan-2026/</link><guid isPermaLink="true">https://uinat.com/news/microsoft-ntlm-deprecation-three-phase-plan-2026/</guid><description>Microsoft will disable the 33-year-old NTLM authentication protocol by default in future Windows releases through a phased rollout: enhanced auditing now, Kerberos improvements in H2 2026, and disabled-by-default in future major releases.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>New n8n Sandbox Escape Vulnerabilities Allow Remote Code Execution</title><link>https://uinat.com/news/n8n-sandbox-escape-jfrog-vulnerabilities-2026/</link><guid isPermaLink="true">https://uinat.com/news/n8n-sandbox-escape-jfrog-vulnerabilities-2026/</guid><description>JFrog discovered two sandbox escape flaws in n8n: CVE-2026-1470 (CVSS 9.9) bypasses JavaScript sandboxing via deprecated &apos;with&apos; statement, and CVE-2026-0863 (CVSS 8.5) escapes Python restrictions via AttributeError.obj.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>PDF Phishing Campaign Harvests Dropbox Credentials via Trusted Cloud Infrastructure</title><link>https://uinat.com/news/pdf-dropbox-phishing-credential-theft-2026/</link><guid isPermaLink="true">https://uinat.com/news/pdf-dropbox-phishing-credential-theft-2026/</guid><description>A phishing campaign uses clean PDF attachments hosted on Vercel to redirect victims to fake Dropbox login pages, bypassing email security by avoiding traditional malware or suspicious links.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>WinRAR Vulnerability Still Widely Exploited by Nation-State and Cybercrime Groups</title><link>https://uinat.com/news/winrar-cve-2025-8088-ongoing-exploitation-2026/</link><guid isPermaLink="true">https://uinat.com/news/winrar-cve-2025-8088-ongoing-exploitation-2026/</guid><description>CVE-2025-8088 (CVSS 8.8), a path traversal flaw abusing Windows Alternate Data Streams, continues to be exploited by Russian APTs, Chinese actors, and cybercriminals to achieve persistence via Startup folder drops.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Panera Bread Data Breach</title><link>https://uinat.com/breaches/panera-bread-shinyhunters-breach-2026/</link><guid isPermaLink="true">https://uinat.com/breaches/panera-bread-shinyhunters-breach-2026/</guid><description>ShinyHunters breached Panera Bread via Microsoft Entra SSO vishing attack, leaking 5.1 million customer records including names, emails, phone numbers, and addresses after the company refused extortion demands.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item></channel></rss>