
Today's Top Cybersecurity News – February 09, 2026 1. Critical 0-Day Remote Code Execution Vulnerability in BeyondTrust Remote Access A critical pre-authentication remote code execution vulnerability (CVE-2026-1731) has been disclosed in BeyondTrust Remote Support and Privileged Remote Access products. This flaw allows attackers to execute arbitrary code remotely without prior authentication, posing a severe risk to affected systems. Sources: Cvefeed, Gbhackers https://cybersecuritynews.com/beyondtrust-remote-access-products-0-day-vulnerability/ 2. TGR-STA-1030 Linux Rootkit Spies on 37 Nations in State-Aligned Campaign The TGR-STA-1030 threat actor has deployed a sophisticated Linux rootkit to conduct cyber espionage targeting government networks across 37 countries between November and December 2025. Multiple critical vulnerabilities, including CVE-2026-1731 and others, were exploited to facilitate stealthy infiltration and data exfiltration. Sources: Bleepingcomputer, Cvefeed https://securityonline.info/jackma-shadowguard-tgr-sta-1030-spies-on-37-nations-via-linux-rootkit/ 3. Two Critical Remote Code Execution Vulnerabilities in detronetdip E-commerce 1.0.0 Two severe vulnerabilities in detronetdip E-commerce 1.0.0 allow remote attackers to bypass authentication via add_seller.php and perform unrestricted file uploads via addadhar.php. Both exploits have been publicly disclosed, increasing the risk of unauthorized access and potential system compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-2165 4. Notepad++ Hack, Office & ESXi 0-Day Vulnerabilities Fuel Ransomware Attacks Recent exploits targeting Notepad++, Microsoft Office, and VMware ESXi have introduced critical zero-day vulnerabilities actively leveraged in ransomware campaigns. These vulnerabilities pose significant risks to enterprise environments, demanding urgent patching and mitigation efforts. Sources: Cvefeed https://cybersecuritynews.com/cybersecurity-newsletter-weekly-february/ 5. Critical Privilege Escalation Vulnerabilities in JAY Login & Register Plugin <= 2.6.03 Two critical privilege escalation vulnerabilities affect the JAY Login & Register WordPress plugin versions up to 2.6.03. Authenticated users with Subscriber access and unauthenticated attackers can exploit these flaws to gain administrator privileges by manipulating user meta via AJAX functions. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-15100 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats
Post summary
The article announces the disclosure of CVE‑2026‑1731, a critical remote‑code‑execution flaw in BeyondTrust Remote Access, and notes its exploitation in the TGR‑STA‑1030 rootkit campaign and other ransomware attacks.


