Friday Wrap Up: 6 February 2026
Another week, another supply chain nightmare. ๐ข
This weekโs cybersecurity roundup features everything from compromised software updates (yes, even Notepad++) to record-breaking DDoS attacks that would make your infrastructure cry. Weโve got nation-state actors playing Olympics spoiler, fintech firms losing millions of records, and AI agents getting their own social network (because apparently they need friends too).
Whether youโre defending against WinRAR exploits or wondering if your antivirus just became your biggest threat, this week had something for everyone.
Check out the full breakdown below โ your threat intel fix is served. โฌ๏ธ
#CyberBreaches #ThreatIntelligence #SupplyChainSecurity #FWU #fridaywrapup
Espionage & Data Extraction
Nation-state actors dominated headlines this week with sophisticated supply chain attacks and targeted espionage campaigns.
๐ฏ Chinese state hackers hijacked Notepad++โs update feature for months, compromising users through a trusted software channel. (Published on 2-Feb-2026, BleepingComputer). Read More
๐ APT28 deployed espionage-focused malware exploiting Microsoft Office CVE-2026-21509 in targeted attacks against high-value systems. (Published on 3-Feb-2026, The Hacker News). Read More
๐ฟ Italy successfully thwarted Russian-linked cyberattacks targeting Winter Olympics websites, according to the Foreign Minister. (Published on 5-Feb-2026, SecurityWeek). Read More
๐ช China-linked DKnife AitM framework targets routers for traffic hijacking and malware delivery through advanced man-in-the-middle techniques. (Published on 6-Feb-2026, The Hacker News). Read More
๐ฆ Amaranth-Dragon exploits WinRAR vulnerability in sophisticated espionage campaigns targeting sensitive organizational data. (Published on 4-Feb-2026, The Hacker News). Read More
Major Cyberattacks & Incidents This week saw multiple high-profile breaches affecting millions of users across various sectors.
๐ ShinyHunters-branded extortion activity expands dramatically with escalating threats against compromised organizations worldwide. (Published on 2-Feb-2026, SecurityWeek). Read More
๐ฅ Hackers leaked 5.1 million Panera Bread customer records exposing personal information in a massive data breach. (Published on 3-Feb-2026, SecurityWeek). Read More
๐ฐ Fintech firm Betterment suffered a data breach exposing 1.4 million customer accounts and sensitive financial information. (Published on 5-Feb-2026, BleepingComputer). Read More
๐ง Newsletter platform Substack notified users of a data breach compromising subscriber information and account credentials. (Published on 5-Feb-2026, BleepingComputer). Read More
โ๏ธ Exposed AWS credentials enabled AI-assisted cloud breach in just 8 minutes, demonstrating automationโs threat potential. (Published on 4-Feb-2026, Hackread). Read More
Malware & Vulnerabilities
Critical vulnerabilities and sophisticated malware strains continued to challenge security teams globally.
๐ก๏ธ eScan Antivirus update servers were compromised to deliver multi-stage malware to unsuspecting users trusting legitimate updates. (Published on 2-Feb-2026, The Hacker News). Read More
๐ฌ Stealthy Windows RAT discovered holding live conversations with operators, enabling real-time command and control capabilities. (Published on 2-Feb-2026, CSO Online). Read More
โ๏ธ Hackers exploited critical React Native Metro bug to breach developer systems through supply chain attacks. (Published on 3-Feb-2026, BleepingComputer). Read More
๐ชฑ GlassWorm malware returns to shatter developer ecosystems with enhanced capabilities targeting software supply chains. (Published on 3-Feb-2026, Dark Reading). Read More
โ ๏ธ Critical n8n workflow automation flaws disclosed publicly along with working exploits posing immediate risk. (Published on 4-Feb-2026, BleepingComputer). Read More
๐ macOS users targeted by Python infostealers disguised as legitimate AI installer packages stealing credentials and data. (Published on 5-Feb-2026, Hackread). Read More
โ๏ธ Fresh SolarWinds vulnerability actively exploited in attacks targeting enterprise infrastructure and management systems. (Published on 4-Feb-2026, SecurityWeek). Read More
๐ฆ New hacking campaign exploits Microsoft Windows WinRAR vulnerability in widespread attacks against Windows users. (Published on 5-Feb-2026, Infosecurity). Read More
๐ Chinese-made malware kit targets Chinese-based routers and edge devices in coordinated infrastructure attacks. (Published on 6-Feb-2026, Infosecurity). Read More
๐ช 17% of third-party OpenClaw add-ons used in cryptocurrency theft and macOS malware distribution campaigns. (Published on 6-Feb-2026, Hackread). Read More
DDoS, Outages & Infrastructure
Record-breaking attacks and persistent botnets tested infrastructure resilience worldwide.
๐ฅ AISURU/Kimwolf botnet launched record-setting 31.4 Tbps DDoS attack, breaking previous volumetric attack records. (Published on 5-Feb-2026, The Hacker News). Read More
๐ค Global SystemBC botnet discovered active across 10,000 infected systems facilitating proxy services and malware delivery. (Published on 4-Feb-2026, Infosecurity). Read More
AI & Policy
Regulatory developments and AI security research shaped policy discussions this week.
๐ก๏ธ NSA published new Zero Trust implementation guidelines providing comprehensive framework for secure architecture deployment. (Published on 2-Feb-2026, Infosecurity). Read More
๐ค Moltbook emerges as social platform where AI agents communicate while humans observe interactions passively. (Published on 3-Feb-2026, Hackread). Read More
๐จ CISA orders federal agencies to replace end-of-life edge devices eliminating unpatched vulnerabilities from networks. (Published on 6-Feb-2026, BleepingComputer). Read More
๐ Claude AI discovered 500 high-severity software vulnerabilities demonstrating AIโs potential in vulnerability research. (Published on 6-Feb-2026, CSO Online). Read More
Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!



