Daily Digest

Critical RCE Flaws in n8n and D-Link Routers Under Active Exploitation; CISA Issues Urgent Warnings

Critical RCE Flaws in n8n and D-Link Routers Under Active Exploitation; CISA Issues Urgent Warnings

January 8, 2026
5 articles (4 new, 1 updated)
15 min read

Summary

This cybersecurity brief for January 8, 2026, covers a series of critical vulnerabilities and active threats. Headlining the news are two maximum-severity (CVSS 10.0) remote code execution flaws in the n8n workflow automation platform, one unauthenticated and one authenticated, prompting urgent patching. Concurrently, a zero-day RCE is being actively exploited in end-of-life D-Link routers, with no patch forthcoming. CISA has added exploited flaws in HPE OneView and legacy PowerPoint to its KEV catalog. Major incidents include a data breach claim against broadband provider Brightspeed by the Crimson Collective, a ransomware attack on claims giant Sedgwick by TridentLocker, and a large-scale SEO poisoning campaign by the Black Cat group. Additionally, reports highlight novel phishing tactics abusing Microsoft 365 and Google Cloud services, and malicious Chrome extensions stealing AI chat data from nearly a million users.

Filter by Category

New Articles (4)

Updated Articles (1)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.