Your complete guide to Microsoft experiences at RSAC™ 2026 Conference

Your complete guide to Microsoft experiences at RSAC™ 2026 Conference

• The era of AI is reshaping both opportunity and risk faster than any shift security leaders have seen. • Every organization is feeling the momentum; and for security teams, the q

Cybersecurity · February 12, 2026 (updated February 24, 2026) · 2 min · 238 words
Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems

Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems

• Cybersecurity researchers have discovered a fresh set of malicious packages across npm and the Python Package Index (PyPI) repository linked to a fake recruitment-themed campaign

Cybersecurity · February 12, 2026 (updated February 24, 2026) · 2 min · 324 words

3D Printer Surveillance

• NY’s 2026-27 budget bill mandates 3D printers to include blocking tech that blocks firearm designs. • The algorithm scans every print file, refusing prints flagged as potential f

Cybersecurity · February 12, 2026 (updated February 24, 2026) · 1 min · 174 words
The CTEM Divide: Why 84% of Security Programs Are Falling Behind

The CTEM Divide: Why 84% of Security Programs Are Falling Behind

• The CTEM Divide: Why 84% of Security Programs Are Falling Behind A new 2026 market intelligence study of 128 enterprise security decision-makers (available here) reveals a stark

Cybersecurity · February 12, 2026 (updated February 24, 2026) · 2 min · 228 words
Senegalese Data Breaches Expose Lack of Security Maturity

Senegalese Data Breaches Expose Lack of Security Maturity

• Cyberattacks & Data Breaches Cyber Risk Data Privacy Cybersecurity Operations News Breaking cybersecurity news, news analysis, commentary, and other content from around the world

Cybersecurity · February 12, 2026 (updated February 24, 2026) · 2 min · 343 words

Bypassing Administrator Protection by Abusing UI Access

• In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didnât exist. • I described one

Cybersecurity · February 12, 2026 (updated February 20, 2026) · 2 min · 268 words
83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure

83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure

• 83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure A significant chunk of the exploitation attempts targeting a newly disclosed security flaw i

Cybersecurity · February 12, 2026 (updated February 17, 2026) · 3 min · 452 words
ISC Stormcast For Thursday, February 12th, 2026 https://isc.sans.edu/podcastdetail/9806, (Thu, Feb 12th)

ISC Stormcast For Thursday, February 12th, 2026 https://isc.sans.edu/podcastdetail/9806, (Thu, Feb 12th)

• ISC Stormcast For Thursday, February 12th, 2026 https://isc.sans.edu/podcastdetail/9806 Handler on Duty: Guy Bruneau Threat Level: green My next class: Application Security: Secu

Cybersecurity · February 12, 2026 (updated February 24, 2026) · 2 min · 420 words
Four Seconds to Botnet - Analyzing a Self Propagating SSH Worm with Cryptographically Signed C2 [Guest Diary], (Wed, Feb 11th)

Four Seconds to Botnet - Analyzing a Self Propagating SSH Worm with Cryptographically Signed C2 [Guest Diary], (Wed, Feb 11th)

• SSH worm exploited weak passwords, compromising Linux systems in seconds. • Attack used credential brute force, uploading a 4.7 KB bash script via SCP. • Script established persi

Cybersecurity · February 12, 2026 (updated February 24, 2026) · 1 min · 169 words
Nation-State Actors Exploit Notepad++ Supply Chain

Nation-State Actors Exploit Notepad++ Supply Chain

• Executive Summary Between June and December 2025, the official hosting infrastructure for the text editor Notepad++ was compromised by a state-sponsored threat group known as Lot

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 1 min · 205 words

North Korea's UNC1069 Hammers Crypto Firms With AI

• In moving away from traditional banks to focus on Web3 companies, the threat actor is leveraging LLMs, deepfakes, legitimate platforms, and ClickFix.

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 1 min · 49 words

How to Stay on Top of Future Threats With a Cutting-Edge SOC

• CISOs should focus on harnessing and securing AI and building new skills among their people. • Vision and change management can transform security.

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 1 min · 50 words
Apple Patches Everything: February 2026, (Wed, Feb 11th)

Apple Patches Everything: February 2026, (Wed, Feb 11th)

• Apple Patches Everything: February 2026 Today, Apple released updates for all of its operating systems (iOS, iPadOS, macOS, tvOS, watchOS, and visionOS). • The update fixes 71 di

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 3 min · 437 words

Automaker Secures the Supply Chain With Developer-Friendly Platform

• How a platform engineering team embeds supply chain security into infrastructure without slowing developers.

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 1 min · 33 words
The strategic SIEM buyer's guide: Choosing an AI-ready platform for the agentic era

The strategic SIEM buyer's guide: Choosing an AI-ready platform for the agentic era

• Share Link copied to clipboard! • Content types Best practices Topics AI and agents Security operations SIEM and XDR As the agentic era reshapes security operations, leaders face

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 2 min · 290 words

Kimwolf Botnet Swamps Anonymity Network I2P

• Kimwolf botnet infected millions of IoT devices, turning them into relays for malicious traffic. • In late 2025, the botnet began targeting I2P to hide control servers from taked

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 1 min · 189 words

AI Rising: Do We Know Enough About the Data Populating It?

• Organizations remain reluctant to address the fact that AI can dangerously expose business operations as well as personal data.

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 1 min · 43 words
The game is over: when 'free' comes at too high a price. What we know about RenEngine

The game is over: when 'free' comes at too high a price. What we know about RenEngine

• Table of Contents Incident analysis Disguise as a visual novel ‘Game’ source files analysis HijackLoader Not only games Distribution Recommendations for protection Indicators of

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 2 min · 228 words

Top Cyber Industry Defenses Spike CO2 Emissions

• Organizations can improve their climate footprints by optimizing two specific cybersecurity protections, without incurring added risks.

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 1 min · 37 words
WSL in the Malware Ecosystem, (Wed, Feb 11th)

WSL in the Malware Ecosystem, (Wed, Feb 11th)

• WSL lets users run a full Linux environment inside Windows, eliminating need for VMs or dual boot. • WSL2’s lightweight virtualized kernel boosts compatibility and performance fo

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 1 min · 177 words

Prompt Injection Via Road Signs

• Prompt Injection Via Road Signs Interesting research: ‘CHAI: Command Hijacking Against Embodied AI.’ Abstract: Embodied Artificial Intelligence (AI) promises to handle edge cases

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 2 min · 263 words

CISA's 2025 Year in Review: Driving Security and Resilience Across Critical Infrastructure

• CISA’s 2025 Year in Review: Driving Security and Resilience Across Critical Infrastructure WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) unveiled its20

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 2 min · 248 words
Spam and phishing in 2025

Spam and phishing in 2025

• The year in figures - 44.99% of all emails sent worldwide and 43.27% of all emails sent in the Russian web segment were spam - 32.50% of all spam emails were sent from Russia - K

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 2 min · 281 words

Asia Fumbles With Throttling Back Telnet Traffic in Region

• Only Taiwan made the top 10 list of governments, effectively blocking the threat-ridden protocol, but overall, the region lagged in curbing Telnet traffic.

Cybersecurity · February 11, 2026 (updated February 24, 2026) · 1 min · 51 words
A Peek Into Muddled Libra's Operational Playbook

A Peek Into Muddled Libra's Operational Playbook

• Executive Summary During a September 2025 incident response investigation, Unit 42 discovered a rogue virtual machine (VM) which we believe with high confidence to be used by the

Cybersecurity · February 10, 2026 (updated February 24, 2026) · 2 min · 306 words

SolarWinds WHD Attacks Highlight Risks of Exposed Apps

• Organizations that have exposed their instances of Web Help Desk to the public Internet have inadvertently made them prime targets for attackers.

Cybersecurity · February 10, 2026 (updated February 24, 2026) · 1 min · 49 words

In Bypassing MFA, ZeroDayRAT Is 'Textbook Stalkerware'

• With access to SIM, location data, and a preview of recent SMSes, attackers have everything they need for account takeover or targeted social engineering.

Cybersecurity · February 10, 2026 (updated February 24, 2026) · 1 min · 53 words
80% of Fortune 500 use active AI Agents: Observability, governance, and security shape the new frontier

80% of Fortune 500 use active AI Agents: Observability, governance, and security shape the new frontier

• Today, Microsoft is releasing the new Cyber Pulse report to provide leaders with straightforward, practical insights and guidance on new cybersecurity risks. • One of today’s mos

Cybersecurity · February 10, 2026 (updated February 24, 2026) · 2 min · 378 words
Manipulating AI memory for profit: The rise of AI Recommendation Poisoning

Manipulating AI memory for profit: The rise of AI Recommendation Poisoning

• That helpful ‘Summarize with AI’ button? • It might be secretly manipulating what your AI recommends. • Microsoft security researchers have discovered a growing trend of AI memor

Cybersecurity · February 10, 2026 (updated February 24, 2026) · 2 min · 231 words

AI-Generated Text and the Detection Arms Race

• AI-Generated Text and the Detection Arms Race In 2023, the science fiction literary magazine Clarkesworld stopped accepting new submissions because so many were generated by arti

Cybersecurity · February 10, 2026 (updated February 24, 2026) · 1 min · 194 words

CISA Releases Guide to Help Critical Infrastructure Users Adopt More Secure Communication

• CISA Releases Guide to Help Critical Infrastructure Users Adopt More Secure Communication WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) today released

Cybersecurity · February 10, 2026 (updated February 24, 2026) · 2 min · 286 words
A one-prompt attack that breaks LLM safety alignment

A one-prompt attack that breaks LLM safety alignment

• Share Link copied to clipboard! • Content types Research Topics Actionable threat insights AI and agents Security management Large language models (LLMs) and diffusion models now

Cybersecurity · February 9, 2026 (updated February 24, 2026) · 2 min · 343 words

LLMs are Getting a Lot Better and Faster at Finding and Exploiting Zero-Days

• LLMs are Getting a Lot Better and Faster at Finding and Exploiting Zero-Days This is amazing: Opus 4.6 is notably better at finding high-severity vulnerabilities than previous mo

Cybersecurity · February 9, 2026 (updated February 24, 2026) · 2 min · 257 words
Analysis of active exploitation of SolarWinds Web Help Desk

Analysis of active exploitation of SolarWinds Web Help Desk

• The Microsoft Defender Research Team observed a multi‑stage intrusion where threat actors exploited internet‑exposed SolarWinds Web Help Desk (WHD) instances to get an initial fo

Cybersecurity · February 7, 2026 (updated February 24, 2026) · 2 min · 370 words
Novel Technique to Detect Cloud Threat Actor Operations

Novel Technique to Detect Cloud Threat Actor Operations

• Executive Summary Cloud-based alerting systems often struggle to distinguish between normal cloud activity and targeted malicious operations by known threat actors. • The difficu

Cybersecurity · February 6, 2026 (updated February 24, 2026) · 2 min · 254 words
New Clickfix variant 'CrashFix' deploying Python Remote Access Trojan

New Clickfix variant 'CrashFix' deploying Python Remote Access Trojan

• In January 2026, Microsoft Defender Experts identified a new evolution in the ongoing ClickFix campaign. • This updated tactic deliberately crashes victims’ browsers and then att

Cybersecurity · February 5, 2026 (updated February 24, 2026) · 2 min · 222 words
The security implementation gap: Why Microsoft is supporting Operation Winter SHIELD

The security implementation gap: Why Microsoft is supporting Operation Winter SHIELD

• Share Link copied to clipboard! • Content types News Topics Office of the CISO Security management Security operations Every conversation I have with information security leaders

Cybersecurity · February 5, 2026 (updated February 24, 2026) · 1 min · 162 words

CISA Orders Federal Agencies to Strengthen Edge Device Security Amid Rising Cyber Threats

• CISA Orders Federal Agencies to Strengthen Edge Device Security Amid Rising Cyber Threats WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) today issuedBin

Cybersecurity · February 5, 2026 (updated February 24, 2026) · 2 min · 270 words
The Shadow Campaigns: Uncovering Global Espionage

The Shadow Campaigns: Uncovering Global Espionage

• Executive Summary This investigation unveils a new cyberespionage group that Unit 42 tracks as TGR-STA-1030. • We refer to the group’s activity as the Shadow Campaigns. • We asse

Cybersecurity · February 5, 2026 (updated February 24, 2026) · 2 min · 217 words
Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT

Stan Ghouls targeting Russia and Uzbekistan with NetSupport RAT

• Introduction Stan Ghouls (also known as Bloody Wolf) is an cybercriminal group that has been launching targeted attacks against organizations in Russia, Kyrgyzstan, Kazakhstan, a

Cybersecurity · February 5, 2026 (updated February 24, 2026) · 2 min · 258 words
Detecting backdoored language models at scale

Detecting backdoored language models at scale

• Today, we are releasing new research on detecting backdoors in open-weight language models. • Our research highlights several key properties of language model backdoors, laying t

Cybersecurity · February 4, 2026 (updated February 24, 2026) · 2 min · 252 words
Why Smart People Fall For Phishing Attacks

Why Smart People Fall For Phishing Attacks

• Threat Research Center Insights Opinions Why Smart People Fall For Phishing Attacks By:Ria Bhatia Ria Bhatia Published:February 3, 2026 Categories:Business Email CompromiseCyberc

Cybersecurity · February 4, 2026 (updated February 24, 2026) · 2 min · 252 words
The Notepad++ supply chain attack - unnoticed execution chains and new IoCs

The Notepad++ supply chain attack - unnoticed execution chains and new IoCs

• UPD 11.02.2026: added recommendations on how to use the Notepad++ supply chain attack rules package in our SIEM system. • Introduction On February 2, 2026, the developers of Note

Cybersecurity · February 3, 2026 (updated February 24, 2026) · 2 min · 269 words

Please Don't Feed the Scattered Lapsus ShinyHunters

• Scattered Lapsus ShinyHunters (SLSH) uses harassment, threats, even swatting to extort firms. • They notify journalists and regulators, amplifying pressure beyond typical ransomw

Cybersecurity · February 2, 2026 (updated February 24, 2026) · 1 min · 181 words
Privileged File System Vulnerability Present in a SCADA System

Privileged File System Vulnerability Present in a SCADA System

• Iconics Suite SCADA system vulnerable (CVE-2025-0921) allows privilege escalation via unnecessary file system operations. • Exploitation can corrupt critical binaries, leading to

Cybersecurity · January 30, 2026 (updated February 24, 2026) · 1 min · 176 words

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

• In the first part of this series, I detailed my journey into macOS security research, which led to the discovery of a type confusion vulnerability (CVE-2024-54529) and a double-f

Cybersecurity · January 30, 2026 (updated February 20, 2026) · 2 min · 281 words
Understanding the Russian Cyberthreat to the 2026 Winter Olympics

Understanding the Russian Cyberthreat to the 2026 Winter Olympics

• Threat Research Center Insights Opinions Understanding the Russian Cyberthreat to the 2026 Winter Olympics By:Justin Moore Justin Moore Published:January 29, 2026 Categories:Cybe

Cybersecurity · January 29, 2026 (updated February 24, 2026) · 2 min · 258 words
Supply chain attack on eScan antivirus: detecting and remediating malicious updates

Supply chain attack on eScan antivirus: detecting and remediating malicious updates

• UPD 30.01.2026: Added technical details about the attack chain and more IoCs. • On January 20, a supply chain attack has occurred, with the infected software being the eScan anti

Cybersecurity · January 29, 2026 (updated February 24, 2026) · 2 min · 215 words

CISA Urges Critical Infrastructure Organizations to Take Action Against Insider Threats

• CISA Urges Critical Infrastructure Organizations to Take Action Against Insider Threats WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) is calling on cri

Cybersecurity · January 28, 2026 (updated February 24, 2026) · 2 min · 281 words
HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns

HoneyMyte updates CoolClient and deploys multiple stealers in recent campaigns

• HoneyMyte upgraded CoolClient backdoor with new features, enhancing persistence and stealth. • The group deployed multiple browser login data stealers across recent campaigns. •

Cybersecurity · January 27, 2026 (updated February 24, 2026) · 1 min · 177 words

Who Operates the Badbox 2.0 Botnet?

• Kimwolf botnet, 2M infected devices, compromised Badbox 2.0 control panel screenshot. • Badbox 2.0: China-based botnet on Android TV streaming boxes, over ten million devices, us

Cybersecurity · January 26, 2026 (updated February 24, 2026) · 1 min · 195 words

Bypassing Windows Administrator Protection

• A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. • The goal of this feature is to replace User Account Control (UAC) with a mo

Cybersecurity · January 26, 2026 (updated February 20, 2026) · 2 min · 251 words
Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense

Happy 9th Anniversary, CTA: A Celebration of Collaboration in Cyber Defense

• CTA founded in 2014, uniting Palo Alto, Fortinet, McAfee, and Symantec for shared threat intelligence. • Shifted industry from proprietary intel to collaborative defense, raising

Cybersecurity · January 24, 2026 (updated February 24, 2026) · 1 min · 184 words

CISA Releases Product Categories List to Propel Post-Quantum Cryptography Adoption Pursuant to President Trump's Executive Order 14306

• CISA releases first product categories list for post‑quantum cryptography (PQC) adoption. • List identifies hardware and software that support or will support PQC standards. • De

Cybersecurity · January 23, 2026 (updated February 24, 2026) · 1 min · 185 words
The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time

The Next Frontier of Runtime Assembly Attacks: Leveraging LLMs to Generate Phishing JavaScript in Real Time

• Attackers embed a benign page that calls an LLM API to generate malicious JavaScript in real time. • Prompt engineering bypasses AI safety guardrails, producing polymorphic phish

Cybersecurity · January 22, 2026 (updated February 24, 2026) · 1 min · 202 words

Kimwolf Botnet Lurking in Corporate, Govt. Networks

• Kimwolf botnet has infected over 2 million IoT devices, enabling massive DDoS attacks. • It scans local networks of compromised systems to spread to additional vulnerable devices

Cybersecurity · January 20, 2026 (updated February 24, 2026) · 2 min · 274 words
DNS OverDoS: Are Private Endpoints Too Private?

DNS OverDoS: Are Private Endpoints Too Private?

Azure Private Endpoints can unintentionally expose resources to DoS attacks. Attack vectors include accidental admin deployments, vendor setups, and malicious actors. Over 5% of Az

Cybersecurity · January 20, 2026 (updated February 24, 2026) · 1 min · 183 words
Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering

Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering

• Threat Research Center Insights Anatomy of an Attack Anatomy of an Attack: The Payroll Pirates and the Power of Social Engineering By:Randy Stone Randy Stone Published:January 16

Cybersecurity · January 17, 2026 (updated February 24, 2026) · 2 min · 255 words

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

• With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland conte

Cybersecurity · January 14, 2026 (updated February 20, 2026) · 2 min · 259 words

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

• Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. • One effect of this change

Cybersecurity · January 14, 2026 (updated February 20, 2026) · 2 min · 307 words