ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 561 by Pierluigi Paganini

criticalData breach exploited in the wildimportance 60CVE-2026-24858CVE-2025-40551CVE-2025-8088

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-40551
Unauthenticated Deserialization RCE in SolarWinds Web Help Desk

SolarWinds Web Help Desk contains a deserialization of untrusted data flaw (CWE-502) that allows an unauthenticated attacker to reach the vulnerable functionality over the network and have it deserialize attacker-supplied input. By sending crafted serialized data, the attacker triggers remote code execution and can run arbitrary commands on the host machine running Web Help Desk. Successful compromise grants control of the help desk server, and observed intrusions include attackers installing Zoho agents and Velociraptor for post-exploitation. Any organization running the product is affected, particularly instances exposed to the internet; the flaw carries a CVSS 9.8 (critical) score and federal agencies are under a CISA (BOD 22-01) patching deadline. The vulnerability is being actively exploited in the wild and was added to the CISA KEV catalog on 2026-02-03, with an EPSS probability of 83.6% that it will be exploited within 30 days.

Do: Upgrade Web Help Desk to the latest patched release per the SolarWinds security advisory (the source data does not specify a fixed version number), and follow BOD 22-01 mitigations or discontinue use if mitigation is not possible, noting the federal patching deadline. Until patched, restrict internet-facing access to the Web Help Desk server. Check hosts for post-exploitation artifacts reported in the wild, such as unexpected Zoho agent installations and Velociraptor, and review logs for unauthenticated requests targeting the application.

9.884% KEV
  • SolarWinds Web Help Desk
large≈ tens of thousands of on-premises deployments worldwide (order of magnitude: 10,000–100,000 systems), an estimate
CVE-2025-8088
WinRAR Path Traversal (CVE-2025-8088) Enables Arbitrary Code Execution

A path traversal flaw (CWE-35) in the Windows version of WinRAR allows attackers to achieve arbitrary code execution by delivering a specially crafted archive file that writes outside the expected location when it is opened or processed. Because the CVSS 4.0 vector indicates a local attack requiring user interaction, victims are typically infected by extracting or previewing a malicious archive received via phishing, a malicious download, or another delivery channel. A successful attacker gains the privileges of the user running WinRAR, providing an initial foothold that has been used for both espionage and ransomware operations. Anyone running the Windows version of WinRAR — one of the most widely deployed Windows desktop utilities — is affected, and CPE data additionally lists dtSearch as an affected vendor. Exploitation is confirmed in the wild by nation-state actors (e.g., the China-linked Amaranth-Dragon group per related reporting) and criminal actors including ransomware operators; the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-12 and carries a near-maximal 94.6% EPSS score.

Do: Update WinRAR to the latest patched release from RARLAB on all Windows endpoints, prioritizing remediation per CISA KEV and BOD 22-01 requirements, and verify that dtSearch deployments bundling the affected component are also updated. Because exploitation requires a user to open or extract a crafted archive, warn users to treat unexpected archive files delivered by email or download with suspicion. Given confirmed ransomware use, hunt across user workstations — not just exposed servers — for suspicious archive-based infections and confirm the patched WinRAR version is installed.

8.495% KEV ransomware
  • RARLAB WinRAR
  • dtsearch
masshundreds of millions of Windows users/devices (est.; RARLAB has historically claimed user counts in the hundreds of millions)
CVE-2026-24858
FortiCloud SSO Authentication Bypass Across Multiple Fortinet Products

CVE-2026-24858 is an authentication bypass (CWE-288) in FortiCloud single sign-on that lets an attacker who owns a FortiCloud account with any registered device log in to other customers' Fortinet devices that have FortiCloud SSO authentication enabled. It affects a wide range of 7.x/8.x builds of FortiOS, FortiProxy, FortiWeb, FortiAnalyzer, FortiManager, FortiNAC-F, and the Siemens RUGGEDCOM APE 1808. An attacker gains unauthorized access to devices registered to other accounts, and related reporting describes FortiGate devices being exploited to breach networks and steal service account credentials. Any organization running an affected build with FortiCloud SSO enabled is exposed. Exploitation is confirmed in the wild: CISA added the flaw to the KEV catalog on 2026-01-27 and Fortinet patched it after active FortiOS SSO exploitation was detected, and EPSS assigns an 86.1% probability of exploitation within 30 days.

Do: Upgrade all affected Fortinet products to the fixed releases specified in Fortinet's PSIRT advisory for CVE-2026-24858; as an interim mitigation, disable FortiCloud SSO authentication on affected devices and audit which devices are registered to your FortiCloud account. Review device logs for unexpected administrative logins or signs of service-account credential theft on FortiGate, and federal agencies must apply mitigations per BOD 22-01 (including CISA's cloud services guidance) or discontinue use of the product.

9.886% KEV
  • Fortinet FortiAnalyzer 7.6.0-7.6.5, 7.4.0-7.4.9, 7.2.0-7.2.11, 7.0.0-7.0.15
  • Fortinet FortiManager 7.6.0-7.6.5, 7.4.0-7.4.9, 7.2.0-7.2.11, 7.0.0-7.0.15
  • Fortinet FortiNAC-F 7.6.3-7.6.5
  • +4 more
masshundreds of thousands of devices potentially affected (Fortinet's FortiGate install base is in the millions and public internet scans have long shown hundreds…
Full article729 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 02, 2026

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

DOJ releases details alleged talented hacker working for Jeffrey Epstein
Cyberattacks Disrupt Communications at Wind, Solar, and Heat Facilities in Poland
SmarterTools patches critical SmarterMail flaw allowing code execution
U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog
Empire Market co-founder faces 10 years to life after guilty plea
SolarWinds addressed four critical Web Help Desk flaws
Google targets IPIDEA in crackdown on global residential proxy networks
Nation-state and criminal actors leverage WinRAR flaw in attacks
OpenSSL issued security updates to fix 12 flaws, including Remote Code Execution
U.S. CISA adds a flaw in multiple Fortinet products to its Known Exploited Vulnerabilities catalog
Fortinet patches actively exploited FortiOS SSO auth bypass (CVE-2026-24858)
PackageGate bugs let attackers bypass protections in NPM, PNPM, VLT, and Bun
WhatsApp rolls out Strict Account settings to strengthen protection for high-risk users
Shadowserver finds 6,000+ likely vulnerable SmarterMail servers exposed online
U.S. CISA adds Microsoft Office, GNU InetUtils, SmarterTools SmarterMail, and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
Amnesia RAT deployed in multi-stage phishing attacks against Russian users
Dormakaba flaws allow to access major organizations’ doors
Emergency Microsoft update fixes in-the-wild Office zero-day
ShinyHunters claims 2 Million Crunchbase records; company confirms breach
Energy sector targeted in multi-stage phishing and BEC campaign using SharePoint
North Korea–linked KONNI uses AI to build stealthy malware tooling
Russia-linked Sandworm APT implicated in major cyber attack on Poland’s power grid
Nike is investigating a possible data breach, after WorldLeaks claims

International Press – Newsletter

Cybercrime

Nike Probes Potential Breach After Threat From Hacking Group 

Crunchbase Confirms Data Breach After Hacking Claims  

ShinyHunters claim hacks of Okta, Microsoft SSO accounts for data theft 

Who Operates the Badbox 2.0 Botnet? 

Retro Phishing: Basic Auth URLs Make a Comeback in Japan 

Chinese Language Money Laundering Networks Emerge as Major Facilitators of the Illicit Crypto Economy, Now Driving 20% of Laundering Activity

Investigation into International “ATM Jackpotting” Scheme and Tren de Aragua results in Additional Indictment and 87 Total Charged Defendants     

Notorious Russia-based RAMP cybercrime forum apparently seized by FBI

Co-Creator of Dark Web Marketplace Pleads Guilty in Chicago to Drug Conspiracy

Former Google Engineer Found Guilty Of Economic Espionage And Theft Of Confidential AI Technology

Malware

Android Trojan Campaign Uses Hugging Face Hosting for RAT Payload Delivery 

Malicious Chrome Extension Performs Hidden Affiliate Hijacking 

CAFE-GB: Scalable and Stable Feature Selection for Malware Detection via Chunk-wise Aggregated Gradient Boosting

Re-Evaluating Android Malware Detection: Tabular Features, Vision Models, and Ensembles

Hacking

Hands-Free Lockpicking: Critical Vulnerabilities in dormakaba’s Physical Access Control System 

Microsoft patches actively exploited Office zero-day vulnerability

Resurgence of a multi‑stage AiTM phishing and BEC campaign abusing SharePoint 

Over 6,000 SmarterMail servers exposed to automated hijacking attacks

PackageGate: 6 Zero-Days in JS Package Managers But NPM Won’t Act  

Fortinet Confirms Active FortiCloud SSO Bypass on Fully Patched FortiGate Firewalls

CVE-2025-40551: Another Solarwinds Web Help Desk Deserialization Issue 

Intelligence and Information Warfare

KONNI Adopts AI to Generate PowerShell Backdoors  

Weaponized in China, Deployed in India: The SyncFuture Espionage Targeted Campaign 

Inside a Multi-Stage Windows Malware Campaign   

Operation DupeHike : UNG0902 targets Russian employees with DUPERUNNER and AdaptixC2     

WhatsApp’s Latest Privacy Protection: Strict Account Settings

PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups  

Space Capabilities to Support Military Operations in the European Theatre 

Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088 

Why a gradual move away from US tech is a good idea  

ELECTRUM: Cyber Attack on Poland’s Electric System 2025

Energy Sector Incident Report – 29 December 2025

Dissecting UAT-8099: New persistence mechanisms and regional focus

Cybersecurity

Defending the 2026 Milano Cortina Winter Games

AI-Powered Disinformation Swarms Are Coming for Democracy   

Fortinet Releases Guidance to Address Ongoing Exploitation of Authentication Bypass Vulnerability CVE-2026-24858

No Place Like Home Network: Disrupting the World’s Largest Residential Proxy Network 

Informant told FBI that Jeffrey Epstein had a ‘personal hacker’ 

US Has Investigated Claims WhatsApp Chats Aren’t Private 

Thousands more Oregon residents learn their health data was stolen in TriZetto breach

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/187524/security/security-affairs-newsletter-round-561-by-pierluigi-paganini-international-edition.html