In the period of February 4-5, 2026, the cybersecurity landscape was dominated by rapid state-sponsored exploitation and critical vulnerability disclosures. The Russian APT28 group weaponized a Microsoft Office zero-day (CVE-2026-21509) within 24 hours to target European governments. Concurrently, a CVSS 10.0 RCE flaw (CVE-2026-21858) in the N8N automation platform left over 100,000 servers vulnerable to takeover. Adding to the incidents, the ShinyHunters collective claimed a major data breach at Harvard University, exposing 115,000 donor records through a sophisticated vishing campaign. Other significant events include patches from Cisco and F5, and CISA adding a SolarWinds flaw to its KEV catalog.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.