<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>UINAT — Security News</title><description>Breaking cybersecurity news and vulnerability disclosures.</description><link>https://uinat.com/</link><item><title>Operation Cronos: How Law Enforcement Dismantled LockBit, the World&apos;s Largest Ransomware Operation</title><link>https://uinat.com/news/lockbit-operation-cronos-takedown-2024/</link><guid isPermaLink="true">https://uinat.com/news/lockbit-operation-cronos-takedown-2024/</guid><description>On February 20, 2024, a 10-country task force seized LockBit&apos;s infrastructure, identified 194 affiliates, and froze $112 million in cryptocurrency in the most significant ransomware takedown in history.</description><pubDate>Fri, 20 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Clop Exploits Oracle E-Business Suite Zero-Days in Massive Extortion Campaign</title><link>https://uinat.com/news/clop-oracle-ebs-zero-day-campaign-2026/</link><guid isPermaLink="true">https://uinat.com/news/clop-oracle-ebs-zero-day-campaign-2026/</guid><description>The Clop ransomware group weaponized CVE-2025-61882 and CVE-2025-61884 to breach nearly 100 organizations including Allianz UK, GlobalLogic, Envoy Air, Harvard, and Washington Post, with ransom demands reaching $50 million.</description><pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Coupang Data Breach Expands: 33.7 Million Accounts Compromised, 165,000 Additional Users Affected</title><link>https://uinat.com/news/coupang-data-breach-33-million-accounts-2026/</link><guid isPermaLink="true">https://uinat.com/news/coupang-data-breach-33-million-accounts-2026/</guid><description>South Korean e-commerce giant Coupang confirmed an additional 165,000 user accounts were exposed in the massive data breach affecting 33.7 million total accounts, triggered by a former employee using valid authentication keys.</description><pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate></item><item><title>China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Southeast Asian Espionage Campaigns</title><link>https://uinat.com/news/amaranth-dragon-apt41-winrar-exploitation-2026/</link><guid isPermaLink="true">https://uinat.com/news/amaranth-dragon-apt41-winrar-exploitation-2026/</guid><description>Check Point Research documents a new threat cluster weaponizing CVE-2025-8088 within days of disclosure to target government and law enforcement agencies across Cambodia, Thailand, Philippines, and neighboring countries.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>DEAD#VAX Campaign Uses IPFS-Hosted VHD Files to Deploy AsyncRAT via Fileless Execution</title><link>https://uinat.com/news/dead-vax-asyncrat-ipfs-campaign-2026/</link><guid isPermaLink="true">https://uinat.com/news/dead-vax-asyncrat-ipfs-campaign-2026/</guid><description>Securonix researchers document a sophisticated malware campaign that chains IPFS hosting, virtual hard disk abuse, and in-memory shellcode injection to deliver AsyncRAT while evading traditional detection.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Metro4Shell: Critical React Native CLI Vulnerability Actively Exploited Against Developers</title><link>https://uinat.com/news/metro4shell-react-native-rce-exploitation-2026/</link><guid isPermaLink="true">https://uinat.com/news/metro4shell-react-native-rce-exploitation-2026/</guid><description>CVE-2025-11953 in React Native CLI&apos;s Metro Development Server is being exploited in the wild to deploy Rust-based malware on developer systems, with attacks observed since December 2025.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>APT28 Deploys LAMEHUG: First Known Malware Using LLMs in Live Operations</title><link>https://uinat.com/news/apt28-lamehug-ai-malware-ukraine-2026/</link><guid isPermaLink="true">https://uinat.com/news/apt28-lamehug-ai-malware-ukraine-2026/</guid><description>Russia&apos;s APT28 has deployed LAMEHUG and PROMPTSTEAL malware that queries large language models via Hugging Face to dynamically generate attack commands, marking the first confirmed use of AI-powered malware in active cyber operations.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>ShinyHunters Publishes Harvard and UPenn Data: 2 Million Records Exposed</title><link>https://uinat.com/news/harvard-upenn-shinyhunters-breach-2026/</link><guid isPermaLink="true">https://uinat.com/news/harvard-upenn-shinyhunters-breach-2026/</guid><description>The ShinyHunters cybercriminal group published stolen data from Harvard University and the University of Pennsylvania after ransom demands went unpaid, exposing over 2 million alumni, donor, and student records.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>New n8n Vulnerability CVE-2026-25049 Bypasses Previous Patch to Enable Remote Code Execution</title><link>https://uinat.com/news/n8n-cve-2026-25049-sandbox-bypass-rce-2026/</link><guid isPermaLink="true">https://uinat.com/news/n8n-cve-2026-25049-sandbox-bypass-rce-2026/</guid><description>A critical flaw in n8n (CVSS 9.4) exploits TypeScript/JavaScript type mismatch to bypass sanitization from a December 2025 patch, enabling authenticated remote command execution via webhook workflows.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>React2Shell Exploitation Enables Massive NGINX Web Traffic Hijacking Campaign</title><link>https://uinat.com/news/react2shell-nginx-traffic-hijacking-campaign-2026/</link><guid isPermaLink="true">https://uinat.com/news/react2shell-nginx-traffic-hijacking-campaign-2026/</guid><description>Threat actors are using CVE-2025-55182 exploitation to inject malicious NGINX configurations that silently redirect web traffic through attacker infrastructure, targeting Asian TLDs and government sites.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate></item><item><title>APT28 Exploits Microsoft Office Zero-Day in Operation Neusploit Targeting Ukraine</title><link>https://uinat.com/news/apt28-operation-neusploit-office-zero-day-2026/</link><guid isPermaLink="true">https://uinat.com/news/apt28-operation-neusploit-office-zero-day-2026/</guid><description>Russia&apos;s APT28 weaponized CVE-2026-21509 within three days of Microsoft&apos;s disclosure, deploying MiniDoor email stealers and PixyNetLoader against Ukraine, Slovakia, and Romania.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Mozilla Adds One-Click Option to Disable All AI Features in Firefox</title><link>https://uinat.com/news/mozilla-firefox-ai-disable-option-2026/</link><guid isPermaLink="true">https://uinat.com/news/mozilla-firefox-ai-disable-option-2026/</guid><description>Firefox 148 introduces a &apos;Block AI enhancements&apos; toggle that disables all current and future generative AI features, plus individual controls for translations, tab grouping, link previews, and chatbot access.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>DockerDash Vulnerability in Ask Gordon AI Enables Code Execution via Image Metadata</title><link>https://uinat.com/news/dockerdash-ai-assistant-vulnerability-2026/</link><guid isPermaLink="true">https://uinat.com/news/dockerdash-ai-assistant-vulnerability-2026/</guid><description>Noma Labs discovered a critical flaw in Docker&apos;s Ask Gordon AI assistant allowing attackers to hijack AI reasoning through malicious image metadata, leading to remote code execution or data exfiltration.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate></item><item><title>NationStates Browser Game Confirms Data Breach After RCE Exploit</title><link>https://uinat.com/news/nationstates-data-breach-rce-user-data-exposed/</link><guid isPermaLink="true">https://uinat.com/news/nationstates-data-breach-rce-user-data-exposed/</guid><description>NationStates shut down its site after a vulnerability reporter chained input sanitization flaws to achieve remote code execution, copying user emails, password hashes, and IP addresses.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Notepad++ Update Mechanism Hijacked by Chinese Threat Actors to Deliver Malware</title><link>https://uinat.com/news/notepad-supply-chain-attack-chinese-threat-actors/</link><guid isPermaLink="true">https://uinat.com/news/notepad-supply-chain-attack-chinese-threat-actors/</guid><description>Lotus Blossom APT compromised Notepad++&apos;s hosting provider to intercept update traffic and deliver the Chrysalis backdoor to targeted government and financial organizations over a six-month period.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Critical vLLM Vulnerability Lets Attackers Hijack AI Servers via Video Link</title><link>https://uinat.com/news/vllm-critical-rce-vulnerability-2026/</link><guid isPermaLink="true">https://uinat.com/news/vllm-critical-rce-vulnerability-2026/</guid><description>CVE-2026-22778, a critical RCE in vLLM versions 0.8.3-0.14.0, chains a PIL information leak with a JPEG2000 heap overflow to achieve code execution through a malicious video link.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>OpenClaw AI Agent Vulnerability Enables One-Click Remote Code Execution</title><link>https://uinat.com/news/openclaw-one-click-rce-vulnerability-2026/</link><guid isPermaLink="true">https://uinat.com/news/openclaw-one-click-rce-vulnerability-2026/</guid><description>CVE-2026-25253 (CVSS 8.8) allows attackers to steal authentication tokens and achieve RCE through a single malicious link via cross-site WebSocket hijacking—even on localhost-only OpenClaw instances.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>400+ Malicious OpenClaw Skills Flood ClawHub With Info-Stealing Malware</title><link>https://uinat.com/news/malicious-openclaw-skills-clawhub-malware-2026/</link><guid isPermaLink="true">https://uinat.com/news/malicious-openclaw-skills-clawhub-malware-2026/</guid><description>Over 400 malicious OpenClaw AI agent skills on ClawHub deploy Atomic Stealer via ClickFix-style social engineering. The hightower6eu account alone published 314 malicious skills targeting crypto and developer credentials.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Microsoft Announces Three-Phase Plan to Disable NTLM by Default</title><link>https://uinat.com/news/microsoft-ntlm-deprecation-three-phase-plan-2026/</link><guid isPermaLink="true">https://uinat.com/news/microsoft-ntlm-deprecation-three-phase-plan-2026/</guid><description>Microsoft will disable the 33-year-old NTLM authentication protocol by default in future Windows releases through a phased rollout: enhanced auditing now, Kerberos improvements in H2 2026, and disabled-by-default in future major releases.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>New n8n Sandbox Escape Vulnerabilities Allow Remote Code Execution</title><link>https://uinat.com/news/n8n-sandbox-escape-jfrog-vulnerabilities-2026/</link><guid isPermaLink="true">https://uinat.com/news/n8n-sandbox-escape-jfrog-vulnerabilities-2026/</guid><description>JFrog discovered two sandbox escape flaws in n8n: CVE-2026-1470 (CVSS 9.9) bypasses JavaScript sandboxing via deprecated &apos;with&apos; statement, and CVE-2026-0863 (CVSS 8.5) escapes Python restrictions via AttributeError.obj.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>PDF Phishing Campaign Harvests Dropbox Credentials via Trusted Cloud Infrastructure</title><link>https://uinat.com/news/pdf-dropbox-phishing-credential-theft-2026/</link><guid isPermaLink="true">https://uinat.com/news/pdf-dropbox-phishing-credential-theft-2026/</guid><description>A phishing campaign uses clean PDF attachments hosted on Vercel to redirect victims to fake Dropbox login pages, bypassing email security by avoiding traditional malware or suspicious links.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>WinRAR Vulnerability Still Widely Exploited by Nation-State and Cybercrime Groups</title><link>https://uinat.com/news/winrar-cve-2025-8088-ongoing-exploitation-2026/</link><guid isPermaLink="true">https://uinat.com/news/winrar-cve-2025-8088-ongoing-exploitation-2026/</guid><description>CVE-2025-8088 (CVSS 8.8), a path traversal flaw abusing Windows Alternate Data Streams, continues to be exploited by Russian APTs, Chinese actors, and cybercriminals to achieve persistence via Startup folder drops.</description><pubDate>Mon, 02 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Automated Extortion Campaign Wipes 1,400 MongoDB Servers, Demands Bitcoin Ransom</title><link>https://uinat.com/news/mongodb-extortion-campaign-1400-servers-wiped/</link><guid isPermaLink="true">https://uinat.com/news/mongodb-extortion-campaign-1400-servers-wiped/</guid><description>A single threat actor is conducting automated attacks against exposed MongoDB instances, wiping databases and demanding 0.005 BTC per server, with 208,500 instances publicly exposed worldwide.</description><pubDate>Sun, 01 Feb 2026 00:00:00 GMT</pubDate></item><item><title>EU AI Act Enforcement Enters Second Year — Commission Review Triggers Potential Expansion</title><link>https://uinat.com/news/eu-ai-act-enforcement-begins-2026/</link><guid isPermaLink="true">https://uinat.com/news/eu-ai-act-enforcement-begins-2026/</guid><description>The European Union&apos;s AI Act marks one year of prohibited AI enforcement on February 2, 2026, triggering Article 112&apos;s mandated Commission review. High-risk AI rules take effect August 2027.</description><pubDate>Sun, 01 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Microsoft Releases Enhanced Security Controls for Copilot for Microsoft 365 Amid Enterprise Data Oversharing Concerns</title><link>https://uinat.com/news/microsoft-copilot-enterprise-security-controls-2026/</link><guid isPermaLink="true">https://uinat.com/news/microsoft-copilot-enterprise-security-controls-2026/</guid><description>Microsoft introduces new Purview DLP integration, sensitivity label enforcement, and oversharing assessment tools for Copilot for Microsoft 365, responding to widespread CISO concerns about AI assistants accessing sensitive data through existing permissions.</description><pubDate>Sun, 01 Feb 2026 00:00:00 GMT</pubDate></item><item><title>CrossCurve DeFi Bridge Exploited for $3M Through Message Validation Bypass</title><link>https://uinat.com/news/crosscurve-bridge-hack-3m-2026/</link><guid isPermaLink="true">https://uinat.com/news/crosscurve-bridge-hack-3m-2026/</guid><description>Attackers drained approximately $3 million from CrossCurve&apos;s cross-chain bridge by spoofing messages to the ReceiverAxelar contract, which lacked proper validation of cross-chain calls.</description><pubDate>Sun, 01 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Varonis Finds &apos;Reprompt&apos; Prompt Injection That Exfiltrates Data From Microsoft Copilot</title><link>https://uinat.com/news/reprompt-attack-microsoft-copilot-varonis-2026/</link><guid isPermaLink="true">https://uinat.com/news/reprompt-attack-microsoft-copilot-varonis-2026/</guid><description>Varonis discovered a prompt injection attack chain that could steal sensitive data from Microsoft Copilot with a single click, bypassing safety filters through double-request and chain-request techniques. Patched January 13, 2026.</description><pubDate>Sun, 01 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Qilin Ransomware Gang Claims Tulsa International Airport Breach</title><link>https://uinat.com/news/tulsa-airport-qilin-ransomware-2026/</link><guid isPermaLink="true">https://uinat.com/news/tulsa-airport-qilin-ransomware-2026/</guid><description>The Russian-speaking Qilin ransomware group listed Tulsa International Airport as a victim, leaking financial documents, employee IDs, and executive communications in the aviation sector&apos;s first reported attack of 2026.</description><pubDate>Sun, 01 Feb 2026 00:00:00 GMT</pubDate></item><item><title>GlassWorm: Self-Spreading Malware Hits VS Code Extensions on Open VSX</title><link>https://uinat.com/news/glassworm-vscode-supply-chain-attack-2026/</link><guid isPermaLink="true">https://uinat.com/news/glassworm-vscode-supply-chain-attack-2026/</guid><description>GlassWorm, a self-propagating worm using Solana blockchain for C2 and invisible Unicode obfuscation, has infected 35,800+ developers through compromised VS Code extensions on Open VSX.</description><pubDate>Sat, 31 Jan 2026 00:00:00 GMT</pubDate></item><item><title>RedKitten: Iran-Linked Group Targets Human Rights NGOs With AI-Written Macros</title><link>https://uinat.com/news/redkitten-iran-ngo-campaign-2026/</link><guid isPermaLink="true">https://uinat.com/news/redkitten-iran-ngo-campaign-2026/</guid><description>HarfangLab uncovered an Iran-linked campaign using AI-generated Office macros and the SloppyMIO backdoor to target activists documenting human rights violations during Iran&apos;s 2025-2026 protests.</description><pubDate>Sat, 31 Jan 2026 00:00:00 GMT</pubDate></item></channel></rss>