Cisco Talos disclosed DKnife, a fully featured gateway-monitoring and adversary‑in‑the‑middle framework with seven Linux-based implants attributed to a China-linked actor. The tooling focuses on edge visibility and traffic interception, and related reporting indicates activity dating back to at least 2019 and spanning desktop, mobile, and IoT ecosystems. Defenders should harden and monitor edge appliances, validate firmware integrity, and lock down certificate/trust and management access paths.
Source: Cisco Talos
CISA: VMware ESXi arbitrary write flaw now leveraged by ransomware
The VMware ESXi vulnerability CVE-2025-22225 has been confirmed in active ransomware campaigns and added to CISA’s Known Exploited Vulnerabilities catalog. Part of a trio of ESXi bugs patched in early 2025, the flaw enables arbitrary writes that can be chained for code execution. Urgently patch ESXi/Workstation/Fusion, restrict management interfaces, and hunt for post-exploitation activity.
Source: Help Net Security
Federal purge of unsupported edge gear: CISA orders removal of end‑of‑life devices
CISA issued a new operational directive requiring federal agencies to identify and remove end-of-life hardware and software—especially at the edge—citing active exploitation. The mandate tightens asset inventories and sets deadlines to rip and replace unsupported devices, shrinking a high-risk attack surface. Private-sector organizations should mirror this posture by accelerating tech refresh and enforcing OEM support baselines.
Source: Recorded Future News
Critical n8n sandbox escape (CVE-2026-25049) enables server-side command execution
A maximum‑severity expression sandbox escape in the n8n open-source automation/AI workflow platform allows attackers with workflow access to execute arbitrary commands on the host. Because n8n often orchestrates secrets and AI agent actions across systems, exploitation risks full server takeover and credential compromise. Patch immediately and review workflow permissions, network egress, and stored credentials.
Source: SecurityWeek
Decade-old EnCase driver resurfaces as an “EDR killer” for 59 security products
Huntress reported adversaries abusing a long‑revoked EnCase kernel driver to terminate or disable 59 endpoint security tools, despite the certificate’s expiration more than a decade ago. The BYOVD technique persists because Windows still allows the driver to load under certain conditions. Organizations should enable driver blocklists (e.g., HVCI/WDAC), review kernel-mode load policies, and monitor for suspicious driver loads.
Source: Help Net Security
Record 31.4 Tbps DDoS attack caps a year of hyper‑volumetric assaults
Cloudflare’s Q4 2025 report details a 31.4 Tbps, 35-second HTTP DDoS attack attributed to AISURU/Kimwolf and a 700% surge in hyper‑volumetric network‑layer events year over year. The data underscores attacker pivot to short, massive bursts designed to outpace capacity and scrubbing. Enterprises should adopt always‑on mitigation, anycast architectures, adaptive rate controls, and automated playbooks.
Source: Cloudflare
Global cyberespionage compromises governments and critical infrastructure in 37 countries
Research tracked compromises at least across 70 institutions in 37 nations, with evidence pointing toward a China-aligned operation. Victims include government bodies and critical infrastructure, with intruders maintaining access for months. The campaign highlights sustained APT persistence—bolster segmentation, enforce strong identity controls, and prioritize long‑dwell detection and threat hunting.
Source: SecurityWeek
You May Also Be Interested In...