A week in security (February 9 – February 15)

A week in security (February 9 – February 15)

• Credential‑stealing Chrome extensions discovered; Malwarebytes Labs offers detection and removal guide. • Fake online shops target Winter Olympics 2026 fans, phishing for payment

Threat Intelligence · February 16, 2026 (updated February 24, 2026) · 1 min · 187 words
How to find and remove credential-stealing Chrome extensions

How to find and remove credential-stealing Chrome extensions

• Researchers have found yet another family of malicious extensions in the Chrome Web Store. • This time, 30 different Chrome extensions were found stealing credentials from more t

Threat Intelligence · February 13, 2026 (updated February 24, 2026) · 1 min · 203 words
Fake shops target Winter Olympics 2026 fans

Fake shops target Winter Olympics 2026 fans

• Fake shops target Winter Olympics 2026 fans If you’ve seen the two stoat siblings serving as official mascots of the Milano Cortina 2026 Winter Olympics, you already know Tina an

Threat Intelligence · February 13, 2026 (updated February 24, 2026) · 2 min · 241 words
ZDI-26-099: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability

ZDI-26-099: Oracle VirtualBox VMSVGA Race Condition Local Privilege Escalation Vulnerability

• Oracle VirtualBox VMSVGA race condition allows local attackers to elevate privileges to hypervisor level. • Exploit requires initial high‑privileged code execution on the guest O

Threat Intelligence · February 13, 2026 (updated February 24, 2026) · 2 min · 347 words
ZDI-26-101: Oracle VirtualBox BusLogic Uninitialized Memory Information Disclosure Vulnerability

ZDI-26-101: Oracle VirtualBox BusLogic Uninitialized Memory Information Disclosure Vulnerability

• Advisory Details Oracle VirtualBox BusLogic Uninitialized Memory Information Disclosure Vulnerability ZDI-26-101ZDI-CAN-28080 This vulnerability allows local attackers to disclos

Threat Intelligence · February 13, 2026 (updated February 24, 2026) · 2 min · 352 words
ZDI-26-103: Oracle VirtualBox VMSVGA Out-Of-Bounds Access Local Privilege Escalation Vulnerability

ZDI-26-103: Oracle VirtualBox VMSVGA Out-Of-Bounds Access Local Privilege Escalation Vulnerability

• Advisory Details Oracle VirtualBox VMSVGA Out-Of-Bounds Access Local Privilege Escalation Vulnerability ZDI-26-103ZDI-CAN-27923 This vulnerability allows local attackers to escal

Threat Intelligence · February 13, 2026 (updated February 24, 2026) · 2 min · 361 words
ZDI-26-104: Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability

ZDI-26-104: Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability

• Advisory Details Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability ZDI-26-104ZDI-CAN-28129 This vulnerability allows remote attackers to

Threat Intelligence · February 13, 2026 (updated February 25, 2026) · 2 min · 221 words
ZDI-26-105: MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

ZDI-26-105: MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability

• Advisory Details MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability ZDI-26-105ZDI-CAN-26649 This vulnerability allows remote attacker

Threat Intelligence · February 13, 2026 (updated February 24, 2026) · 2 min · 219 words
Hand over the keys for Shannon's shenanigans

Hand over the keys for Shannon's shenanigans

• Hand over the keys for Shannon’s shenanigans Welcome to this week’s edition of the Threat Source newsletter. • Last week, yet another security AI tool made the rounds on social m

Threat Intelligence · February 12, 2026 (updated February 24, 2026) · 2 min · 305 words
Outlook add-in goes rogue and steals 4,000 credentials and payment data

Outlook add-in goes rogue and steals 4,000 credentials and payment data

• Outlook add-in goes rogue and steals 4,000 credentials and payment data Researchersfound a malicious Microsoft Outlook add-in which was able to steal 4,000 stolen Microsoft accou

Threat Intelligence · February 12, 2026 (updated February 24, 2026) · 2 min · 238 words
GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use

GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use

• GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use Google Threat Intelligence Group Google Threat Intelligence Visibilit

Threat Intelligence · February 12, 2026 (updated February 26, 2026) · 2 min · 267 words
Child exploitation, grooming, and social media addiction claims put Meta on trial

Child exploitation, grooming, and social media addiction claims put Meta on trial

• Child exploitation, grooming, and social media addiction claims put Meta on trial Meta is facing two trials over child safety allegations in California and New Mexico. • The laws

Threat Intelligence · February 12, 2026 (updated February 24, 2026) · 2 min · 244 words
Ryan Liles, master of technical diplomacy

Ryan Liles, master of technical diplomacy

• Ryan Liles, master of technical diplomacy Cisco Talos is back with another inside look at the people who keep the internet safe. • This time, Amy chats with Ryan Liles, who bridg

Threat Intelligence · February 12, 2026 (updated February 24, 2026) · 2 min · 241 words
Criminals are using AI website builders to clone major brands

Criminals are using AI website builders to clone major brands

• Cybercriminals use AI website builders like Vercel to clone trusted brands in minutes. • Cheap, fast domain registration lets attackers register plausible brand‑lookalike names w

Threat Intelligence · February 12, 2026 (updated February 24, 2026) · 1 min · 211 words

Bypassing Administrator Protection by Abusing UI Access

• In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didnât exist. • I described one

Threat Intelligence · February 12, 2026 (updated February 24, 2026) · 2 min · 259 words
ZDI-26-094: Schneider Electric EcoStruxure Power Build SSD File Parsing Use-After-Free Remote Code Execution Vulnerability

ZDI-26-094: Schneider Electric EcoStruxure Power Build SSD File Parsing Use-After-Free Remote Code Execution Vulnerability

• Advisory Details Schneider Electric EcoStruxure Power Build SSD File Parsing Use-After-Free Remote Code Execution Vulnerability ZDI-26-094ZDI-CAN-27478 This vulnerability allows

Threat Intelligence · February 12, 2026 (updated February 24, 2026) · 3 min · 564 words
Malwarebytes earns PCMag Best Tech Brand spot, scores 100% with MRG Effitas

Malwarebytes earns PCMag Best Tech Brand spot, scores 100% with MRG Effitas

• Malwarebytes earns PCMag Best Tech Brand spot, scores 100% with MRG Effitas Malwarebytes is on a roll. • Recently named one of PCMag’s ‘Best Tech Brands for 2026,’ Malwarebytes a

Threat Intelligence · February 11, 2026 (updated February 24, 2026) · 1 min · 186 words
New threat actor, UAT-9921, leverages VoidLink framework in campaigns

New threat actor, UAT-9921, leverages VoidLink framework in campaigns

• - Cisco Talos recently discovered a new threat actor, UAT-9921, leveraging VoidLink in campaigns. • Their activities may go as far back as 2019, even without VoidLink. • - The Vo

Threat Intelligence · February 11, 2026 (updated February 24, 2026) · 1 min · 208 words
The February 2026 Security Update Review

The February 2026 Security Update Review

• I have survived the biggest Pwn2Own ever, but I’m back in Tokyo for the second Patch Tuesday of 2026. • My location never stops Patch Tuesday from coming, so let’s take a look at

Threat Intelligence · February 10, 2026 (updated February 24, 2026) · 3 min · 559 words
Discord will limit profiles to teen-appropriate mode until you verify your age

Discord will limit profiles to teen-appropriate mode until you verify your age

• Discord will limit profiles to teen-appropriate mode until you verify your age Discordannouncedit will put all existing and new profiles in teen-appropriate mode by default in ea

Threat Intelligence · February 10, 2026 (updated February 24, 2026) · 2 min · 281 words
Beyond the Battlefield: Threats to the Defense Industrial Base

Beyond the Battlefield: Threats to the Defense Industrial Base

• Beyond the Battlefield: Threats to the Defense Industrial Base Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most.

Threat Intelligence · February 10, 2026 (updated February 25, 2026) · 2 min · 284 words
How safe are kids using social media? We did the groundwork

How safe are kids using social media? We did the groundwork

• When researchers created an account for a child under 13 on Roblox, they expected heavy guardrails. • Instead, they found that the platform’s search features still allowed kids t

Threat Intelligence · February 10, 2026 (updated February 24, 2026) · 2 min · 215 words
Man tricked hundreds of women into handing over Snapchat security codes

Man tricked hundreds of women into handing over Snapchat security codes

• Man tricked hundreds of women into handing over Snapchat security codes Fresh off a breathless Super Bowl Sunday, we’re less thrilled to bring you this week’s Weirdo Wednesday. •

Threat Intelligence · February 10, 2026 (updated February 24, 2026) · 2 min · 224 words
UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering

UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering

• UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering Mandiant Written by: Ross Inman, Adrian Hernandez Introduction North Korean threat actors

Threat Intelligence · February 9, 2026 (updated February 25, 2026) · 2 min · 299 words
9th February - Threat Intelligence Report

9th February - Threat Intelligence Report

• Conpet pipeline attack disrupted IT but not operations. • Qilin ransomware group claimed responsibility. • Check Point Harmony protects against this threat. • Report covers recen

Threat Intelligence · February 9, 2026 (updated February 24, 2026) · 3 min · 543 words
All gas, no brakes: Time to come to AI church

All gas, no brakes: Time to come to AI church

• All gas, no brakes: Time to come to AI church Welcome to this week’s edition of the Threat Source newsletter. • Brothers and sisters, gather close for a moment. • We are all secu

Threat Intelligence · February 5, 2026 (updated February 24, 2026) · 2 min · 220 words
CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewall

CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewall

• CVE-2025-6978 exposes command injection in Arista NG Firewall’s diagnostics component. • Remote authenticated attackers can craft HTTP requests to execute arbitrary commands as r

Threat Intelligence · February 5, 2026 (updated February 24, 2026) · 1 min · 164 words
Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework

Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework

• - Cisco Talos uncovered ‘DKnife,’ a fully featured gateway-monitoring and adversary-in-the-middle (AitM) framework comprising seven Linux-based implants that perform deep-packet

Threat Intelligence · February 5, 2026 (updated February 24, 2026) · 2 min · 262 words
Amaranth-Dragon: Weaponizing CVE-2025-8088 for Targeted Espionage in the Southeast Asia

Amaranth-Dragon: Weaponizing CVE-2025-8088 for Targeted Espionage in the Southeast Asia

• Check Point Research has identified several campaigns targeting multiple countries in the Southeast Asian region. • These related activities have been collectively categorized un

Threat Intelligence · February 4, 2026 (updated February 25, 2026) · 2 min · 226 words
2nd February - Threat Intelligence Report

2nd February - Threat Intelligence Report

• FILTER BY YEAR 2026 2025 2024 2023 2022 2021 2020 2019 2018 2017 2016 2nd February - Threat Intelligence Report For the latest discoveries in cyber research for the week of 2nd F

Threat Intelligence · February 2, 2026 (updated February 24, 2026) · 2 min · 368 words
Guidance from the Frontlines: Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaS

Guidance from the Frontlines: Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaS

• Guidance from the Frontlines: Proactive Defense Against ShinyHunters-Branded Data Theft Targeting SaaS Mandiant Introduction Mandiant is tracking a significant expansion and esca

Threat Intelligence · January 30, 2026 (updated February 24, 2026) · 2 min · 272 words
Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft

Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft

• Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft Mandiant Google Threat Intelligence Visibility and context on the threats that matter most. • C

Threat Intelligence · January 30, 2026 (updated February 24, 2026) · 2 min · 293 words
Celebrating our 2025 open-source contributions

Celebrating our 2025 open-source contributions

• Celebrating our 2025 open-source contributions Last year, our engineers submitted over 375 pull requests that were merged into non-Trail of Bits repositories, touching more than

Threat Intelligence · January 30, 2026 (updated February 24, 2026) · 2 min · 238 words

Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529

• CVE-2024-54529: type confusion in CoreAudio’s com.apple.audio.audiohald Mach service, causing crashes. • Exploitation involved manipulating Mach messages to fetch wrong HALS_Obje

Threat Intelligence · January 30, 2026 (updated February 24, 2026) · 1 min · 173 words
I'm locked in!

I'm locked in!

• Welcome to this week’s edition of the Threat Source newsletter. • I’ve struggled a lot over the last few years with balance. • I want to follow the news closely, but at the same

Threat Intelligence · January 29, 2026 (updated February 24, 2026) · 2 min · 239 words
Microsoft releases update to address zero-day vulnerability in Microsoft Office

Microsoft releases update to address zero-day vulnerability in Microsoft Office

• Microsoft releases update to address zero-day vulnerability in Microsoft Office Microsoft has published three out-of-band (OOB) updates so far in January 2026. • One of these upd

Threat Intelligence · January 29, 2026 (updated February 24, 2026) · 2 min · 226 words
Building cryptographic agility into Sigstore

Building cryptographic agility into Sigstore

• Sigstore’s original hard-coded ECDSA P-256 + SHA-256 limited future cryptographic flexibility. • Trail of Bits collaborated to create centralized algorithm registry in Protobuf s

Threat Intelligence · January 29, 2026 (updated February 24, 2026) · 1 min · 155 words
Dissecting UAT-8099: New persistence mechanisms and regional focus

Dissecting UAT-8099: New persistence mechanisms and regional focus

• - Cisco Talos has identified a new campaign by UAT-8099, active from late 2025 to early 2026, that is targeting vulnerable Internet Information Services (IIS) servers across Asia

Threat Intelligence · January 29, 2026 (updated February 24, 2026) · 2 min · 246 words
IR Trends Q4 2025: Exploitation remains dominant, phishing campaign targets Native American tribal organizations

IR Trends Q4 2025: Exploitation remains dominant, phishing campaign targets Native American tribal organizations

• Threat actors predominately exploited public-facing applications for the second quarter in a row, with this tactic appearing in nearly 40 percent of Cisco Talos Incident Response

Threat Intelligence · January 29, 2026 (updated February 24, 2026) · 2 min · 289 words
Cyber Security Report 2026

Cyber Security Report 2026

• CATEGORIES Android Malware23 Artificial Intelligence4 ChatGPT3 Check Point Research Publications443 Cloud Security1 CPRadio44 Crypto2 Data & Threat Intelligence1 Data Analysis0 D

Threat Intelligence · January 28, 2026 (updated February 24, 2026) · 2 min · 317 words
No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network

No Place Like Home Network: Disrupting the World's Largest Residential Proxy Network

• No Place Like Home Network: Disrupting the World’s Largest Residential Proxy Network Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the thr

Threat Intelligence · January 28, 2026 (updated February 24, 2026) · 2 min · 276 words
Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088

Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088

• CVE-2025-8088: critical path traversal flaw in WinRAR allows arbitrary file writes via ADS. • Exploited by state-backed actors from Russia, China and financially motivated groups

Threat Intelligence · January 27, 2026 (updated February 24, 2026) · 1 min · 168 words

26th January - Threat Intelligence Report

• Article inaccessible; requires JavaScript to load content. • Unable to verify authenticity of threat intel data. • No actionable insights provided due to technical barrier. • Sug

Threat Intelligence · January 26, 2026 (updated February 24, 2026) · 1 min · 133 words

Bypassing Windows Administrator Protection

• Windows 11 25H2 introduces Administrator Protection, replacing UAC with a stricter privilege model. • Feature grants admin rights only when necessary, isolating limited and admin

Threat Intelligence · January 26, 2026 (updated February 24, 2026) · 1 min · 162 words
I scan, you scan, we all scan for... knowledge?

I scan, you scan, we all scan for... knowledge?

• Reconnaissance is often ignored, yet it’s essential for protecting networks. • Know your environment: attackers excel at mapping assets, from Windows 7 machines to smart fridges.

Threat Intelligence · January 22, 2026 (updated February 24, 2026) · 1 min · 194 words
Foxit, Epic Games Store, MedDreams vulnerabilities

Foxit, Epic Games Store, MedDreams vulnerabilities

• Cisco Talos uncovered 25 critical vulnerabilities across Foxit PDF Editor, Epic Games Store, and MedDreams PACS. • Foxit PDF Editor had privilege escalation via Microsoft Store i

Threat Intelligence · January 22, 2026 (updated February 24, 2026) · 1 min · 194 words

KONNI Adopts AI to Generate PowerShell Backdoors

• KONNI leverages AI to auto-generate PowerShell backdoor scripts, streamlining malware development. • AI models produce obfuscated code, enhancing stealth against signature-based

Threat Intelligence · January 22, 2026 (updated February 24, 2026) · 1 min · 187 words
Pwn2Own Automotive 2026 - Day One Results

Pwn2Own Automotive 2026 - Day One Results

• 76 unique 0‑day vulnerabilities discovered across three days, totaling $1,047,000 in rewards. • Fuzzware.io clinched Master of Pwn with 28 points, outperforming rivals like Team

Threat Intelligence · January 21, 2026 (updated February 24, 2026) · 3 min · 465 words
Pwn2Own Automotive 2026 - The Full Schedule

Pwn2Own Automotive 2026 - The Full Schedule

• Pwn2Own Automotive 2026 returns to Tokyo, featuring record 73 entries. • Competition spans real‑world automotive components, testing IVI and Level‑2 EV chargers. • Random draw se

Threat Intelligence · January 20, 2026 (updated February 24, 2026) · 1 min · 210 words

VoidLink: Evidence That the Era of Advanced AI-Generated Malware Has Begun

• VoidLink showcases AI-generated malware capable of crafting polymorphic code. • The malware leverages generative models to evade traditional signature-based detection. • Checkpoi

Threat Intelligence · January 20, 2026 (updated February 24, 2026) · 1 min · 168 words

19th January - Threat Intelligence Report

• Unable to access threat intel report due to JavaScript requirement, preventing data retrieval. • Checkpoint Research site blocked without JavaScript, limiting threat intelligence

Threat Intelligence · January 19, 2026 (updated February 24, 2026) · 1 min · 167 words
Predicting 2026

Predicting 2026

• Predicting 2026 Welcome to this week’s edition of the Threat Source newsletter. • It’s become traditional at this time of year to make predictions about cybersecurity for the com

Threat Intelligence · January 15, 2026 (updated February 24, 2026) · 2 min · 232 words
Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation

Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation

• Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation Stop attacks, reduce risk, and advance your security. • Written by: Nic Losby Introduc

Threat Intelligence · January 15, 2026 (updated February 24, 2026) · 2 min · 241 words
UAT-8837 targets critical infrastructure sectors in North America

UAT-8837 targets critical infrastructure sectors in North America

• - Cisco Talos is closely tracking UAT-8837, a threat actor we assess with medium confidence is a China-nexus advanced persistent threat (APT) actor based on overlaps in tactics,

Threat Intelligence · January 15, 2026 (updated February 24, 2026) · 2 min · 296 words

A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave

• With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland conte

Threat Intelligence · January 14, 2026 (updated February 24, 2026) · 2 min · 261 words

A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby

• Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. • One effect of this change

Threat Intelligence · January 14, 2026 (updated February 24, 2026) · 2 min · 330 words

Sicarii Ransomware: Truth vs Myth

• JavaScript is disabled In order to continue, we need to verify that you’re not a robot. • This requires JavaScript. • Enable JavaScript and then reload the page.

Threat Intelligence · January 14, 2026 (updated February 24, 2026) · 1 min · 132 words
The January 2026 Security Update Review

The January 2026 Security Update Review

• I may be in Tokyo preparing for Pwn2Own Automotive, but that doesn’t stop patch Tuesday from coming. • Put aside your broken New Year’s resolutions for just a moment as we review

Threat Intelligence · January 13, 2026 (updated February 24, 2026) · 2 min · 413 words
Lack of isolation in agentic browsers resurfaces old vulnerabilities

Lack of isolation in agentic browsers resurfaces old vulnerabilities

• Lack of isolation in agentic browsers resurfaces old vulnerabilities With browser-embedded AI agents, we’re essentially starting the security journey over again. • We exploited a

Threat Intelligence · January 13, 2026 (updated February 24, 2026) · 2 min · 231 words

Unveiling VoidLink - A Stealthy, Cloud-Native Linux Malware Framework

• JavaScript is disabled In order to continue, we need to verify that you’re not a robot. • This requires JavaScript. • Enable JavaScript and then reload the page.