Arkanix Stealer: a C++ & Python infostealer

Arkanix Stealer: a C++ & Python infostealer

• Introduction In October 2025, we discovered a series of forum posts advertising a previously unknown stealer, dubbed ‘Arkanix Stealer’ by its authors. • It operated under a MaaS

Cybersecurity · February 19, 2026 (updated February 25, 2026) · 2 min · 244 words
OpenClaw Security Issues Continue as SecureClaw Open Source Tool Debuts

OpenClaw Security Issues Continue as SecureClaw Open Source Tool Debuts

• OpenClaw is rarely out of the news, but not necessarily under that name. • This ‘autonomous personal assistant’ started life as Clawdbot, changed its name to Moltbot, and is now

Cybersecurity · February 19, 2026 (updated February 24, 2026) · 2 min · 223 words
Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users

Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users

• Fake IPTV Apps Spread Massiv Android Malware Targeting Mobile Banking Users Cybersecurity researchers have disclosed details of a new Android trojan calledMassivthat’s designed t

Cybersecurity · February 19, 2026 (updated February 24, 2026) · 2 min · 321 words
New 'Massiv' Android banking malware poses as an IPTV app

New 'Massiv' Android banking malware poses as an IPTV app

• New ‘Massiv’ Android banking malware poses as an IPTV app February 19, 2026 05:00 AM 0 A new Android banking malware, which researchers named Massiv, is posing as an IPTV app to

Cybersecurity · February 19, 2026 (updated February 24, 2026) · 2 min · 348 words
German Rail Giant Deutsche Bahn Hit by Large-Scale DDoS Attack

German Rail Giant Deutsche Bahn Hit by Large-Scale DDoS Attack

• Deutsche Bahn, Germany’s national rail operator, has been dealing with a large-scale distributed denial-of-service (DDoS) attack that has disrupted some of its IT systems.Regular

Cybersecurity · February 19, 2026 (updated February 24, 2026) · 2 min · 395 words
CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware

CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware

• CRESCENTHARVEST Campaign Targets Iran Protest Supporters With RAT Malware Cybersecurity researchers have disclosed details of a new campaign dubbedCRESCENTHARVEST, likely targeti

Cybersecurity · February 19, 2026 (updated February 24, 2026) · 2 min · 306 words
February 2026 Patch Tuesday: Six Zero-Days Among 59 CVEs Patched

February 2026 Patch Tuesday: Six Zero-Days Among 59 CVEs Patched

• Patch Tuesday 2026 fixed 59 CVEs, including six critical zero‑days. • CVE‑2026‑21533: Windows Remote Desktop elevation of privilege, CVSS 7.8. • Exploit modifies service config k

Cybersecurity · February 19, 2026 (updated February 24, 2026) · 3 min · 508 words

More Than 40% of South Africans Were Scammed in 2025

• Survey underscores the reality that scammers follow ‘scalable opportunities and low friction,’ rather than rich targets that tend to be better protected.

Cybersecurity · February 19, 2026 (updated February 25, 2026) · 1 min · 113 words
ISC Stormcast For Thursday, February 19th, 2026 https://isc.sans.edu/podcastdetail/9816, (Thu, Feb 19th)

ISC Stormcast For Thursday, February 19th, 2026 https://isc.sans.edu/podcastdetail/9816, (Thu, Feb 19th)

• ISC Stormcast For Thursday, February 19th, 2026 https://isc.sans.edu/podcastdetail/9816 Handler on Duty: Johannes Ullrich Threat Level: green My next class: Application Security:

Cybersecurity · February 19, 2026 (updated February 25, 2026) · 2 min · 291 words
How to start consolidating your cybersecurity tools

How to start consolidating your cybersecurity tools

• How to start consolidating your cybersecurity tools Jackson Connell, Mitch Pronschinske Optimize operations Risk & compliance Culture & collaboration Jan 12, 2026 Jackson Connell

The risks of cybersecurity tool sprawl: Why consolidation is a strategic priority

The risks of cybersecurity tool sprawl: Why consolidation is a strategic priority

• The risks of cybersecurity tool sprawl: Why consolidation is a strategic priority Jackson Connell, Mitch Pronschinske Optimize operations Risk & compliance Culture & collaboratio

Exposing Insider Threats through Data Protection, Identity, and HR Context

Exposing Insider Threats through Data Protection, Identity, and HR Context

• Insider threats pose a growing risk to organizations. • Whether insiders take malicious actions, exhibit negligent behavior, or make accidental errors, they have the potential to

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 3 min · 602 words

Scam Abuses Gemini Chatbots to Convince People to Buy Fake Crypto

• A convincing presale site for phony ‘Google Coin’ features an AI assistant that engages victims with a slick sales pitch, funneling payment to attackers.

Cybersecurity · February 18, 2026 (updated February 25, 2026) · 1 min · 135 words

Critical Grandstream VoIP Bug Highlights SMB Security Blind Spot

• CVE-2026-2329 allows unauthenticated root-level access to SMB phone infrastructure, so attackers can intercept calls, commit toll fraud, and impersonate users.

Cybersecurity · February 18, 2026 (updated February 25, 2026) · 1 min · 123 words
Critical infra Honeywell CCTVs vulnerable to auth bypass flaw

Critical infra Honeywell CCTVs vulnerable to auth bypass flaw

• Critical infra Honeywell CCTVs vulnerable to auth bypass flaw February 18, 2026 03:58 PM 0 The U.S. • Cybersecurity and Infrastructure Security Agency (CISA) is warning of a crit

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 379 words

Threat Intelligence Has a Human-Shaped Blind Spot

• How I realized what I was taught to about threat intelligence was missing something crucial.

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 1 min · 115 words

Dell's Hard-Coded Flaw: A Nation-State Goldmine

• A China-related attacker has exploited the vendor flaw since mid-2024, allowing it to move laterally, maintain persistent access, and deploy malware.

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 1 min · 112 words
AI platforms can be abused for stealthy malware communication

AI platforms can be abused for stealthy malware communication

• AI platforms can be abused for stealthy malware communication February 18, 2026 03:18 PM 0 AI assistants like Grok and Microsoft Copilot with web browsing and URL-fetching capabi

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 359 words
A CISO's Playbook for Defending Data Assets Against AI Scraping

A CISO's Playbook for Defending Data Assets Against AI Scraping

• Cyber Risk Commentary Cybersecurity In-Depth: Getting answers to questions about IT security threats and best practices from trusted cybersecurity professionals and industry expe

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 259 words
AI Unlocked Decoding Prompt Injection Interactive Challenge

AI Unlocked Decoding Prompt Injection Interactive Challenge

• AI Unlocked challenge focuses on detecting and mitigating prompt injection attacks. • Participants learn to craft prompts that resist malicious manipulation by LLMs. • Interactiv

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 3 min · 547 words
Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist's Phone in Police Custody

Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist's Phone in Police Custody

• Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist’s Phone in Police Custody New research from the Citizen Lab has found signs that Kenyan authorities used a commercialfor

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 418 words
Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution

Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution

• Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution Cybersecurity researchers have disclosed a critical security flaw in the Grandstream GXP1600 seri

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 4 min · 646 words
Telegram channels expose rapid weaponization of SmarterMail flaws

Telegram channels expose rapid weaponization of SmarterMail flaws

• SmarterMail CVE-2026-24423 and CVE-2026-23760 enable remote code execution and auth bypass. • Attackers weaponized these flaws within days of disclosure, sharing exploits on Tele

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 246 words
Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages

Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages

• Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages February 18, 2026 11:26 AM 0 Microsoft says an Exchange Online issue that mistakenly quarantined legitima

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 352 words
New Keenadu Android Malware Found on Thousands of Devices

New Keenadu Android Malware Found on Thousands of Devices

• Researchers at Kaspersky have analyzed a recently discovered Android malware that enables its operators to remotely control compromised devices.DubbedKeenadu, the backdoor has be

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 418 words
Cogent Security Raises $42 Million for AI-Driven Vulnerability Management

Cogent Security Raises $42 Million for AI-Driven Vulnerability Management

• Cogent Security raises $42M Series A, total funding now $53M. • Funding led by Bain Capital Ventures, joined by Greylock, OpenAI execs, Datadog. • Company develops autonomous AI

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 1 min · 176 words
Data breach at fintech firm Figure affects nearly 1 million accounts

Data breach at fintech firm Figure affects nearly 1 million accounts

• Hackers breached Figure Technology Solutions, stealing personal data of nearly 1 million accounts. • Attack was a social‑engineering phishing that tricked an employee into giving

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 273 words
Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration

Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration

• 16 critical, high, and medium‑severity vulnerabilities found in Foxit and Apryse PDF platforms. • Flaws include DOM XSS, SSRF, path traversal, and OS command injection. • Attacke

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 1 min · 175 words
Lenovo denies allegations of transferring data to China - class action lawsuit alleges company uses trackers to expose American behavioral data to 'foreign adversaries'

Lenovo denies allegations of transferring data to China - class action lawsuit alleges company uses trackers to expose American behavioral data to 'foreign adversaries'

• Lenovo sued by Almeida Law Group for alleged data transfer to China. • Lawsuit claims violation of DOJ Data Security Program, preventing large data exports to ‘countries of conce

AI Found Twelve New Vulnerabilities in OpenSSL

• AI Found Twelve New Vulnerabilities in OpenSSL The title of the post is’What AI Security Research Looks Like When It Works,’ and I agree: In the latest OpenSSL security release>

Cybersecurity · February 18, 2026 (updated February 25, 2026) · 2 min · 258 words
Microsoft says bug causes Copilot to summarize confidential emails

Microsoft says bug causes Copilot to summarize confidential emails

• Microsoft says a Microsoft 365 Copilot bug has been causing the AI assistant to summarize confidential emails since late January, bypassing data loss prevention (DLP) policies th

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 301 words
Cybersecurity Tech Predictions for 2026: Operating in a World of Permanent Instability

Cybersecurity Tech Predictions for 2026: Operating in a World of Permanent Instability

• In 2025, navigating the digital seas still felt like a matter of direction. • Organizations charted routes, watched the horizon, and adjusted course to reach safe harbors of resi

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 294 words
Glendale man gets 5 years in prison for role in darknet drug ring

Glendale man gets 5 years in prison for role in darknet drug ring

• Glendale man gets 5 years in prison for role in darknet drug ring February 18, 2026 05:50 AM 0 ​A Glendale man was sentenced to nearly five years in federal prison for his role i

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 272 words
3 Ways to Start Your Intelligent Workflow Program

3 Ways to Start Your Intelligent Workflow Program

• 3 Ways to Start Your Intelligent Workflow Program Security, IT, and engineering teams today are under relentless pressure to accelerate outcomes, cut operational drag, and unlock

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 353 words
Palo Alto Networks to Acquire Koi in Reported $400 Million Transaction

Palo Alto Networks to Acquire Koi in Reported $400 Million Transaction

• Palo Alto Networks announced on Tuesday that it has entered into a definitive agreement to acquire endpoint security company Koi.Financial details have not been disclosed by the

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 338 words
Tracking Malware Campaigns With Reused Material, (Wed, Feb 18th)

Tracking Malware Campaigns With Reused Material, (Wed, Feb 18th)

• Tracking Malware Campaigns With Reused Material A few days ago I wrote a diary called ‘Malicious Script Delivering More Maliciousness’[1]. • In the malware infection chain, there

Cybersecurity · February 18, 2026 (updated February 25, 2026) · 2 min · 300 words
Notepad++ Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware

Notepad++ Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware

• Notepad++ released 8.9.2 patch to fix hijacked update mechanism exploited by Chinese threat actor. • Introduces ‘double lock’ design, verifying signed installer and XML from upda

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 2 min · 299 words
What Aristotle and Socrates can teach us about using generative AI

What Aristotle and Socrates can teach us about using generative AI

• AI language models can erode our creative capacity, making original idea generation harder. • Other AI types enhance critical thinking, providing analytical tools for better deci

Singapore & Its 4 Major Telcos Fend Off Chinese Hackers

Singapore & Its 4 Major Telcos Fend Off Chinese Hackers

• Singapore’s CSA and four telcos launched ‘Cyber Guardian’ to counter China-linked UNC3886.\n• 100+ incident responders coordinated across government and M1, Singtel, StarHub, Sim

Cybersecurity · February 18, 2026 (updated February 24, 2026) · 1 min · 177 words
Spain orders NordVPN and ProtonVPN to block LaLiga stream piracy

Spain orders NordVPN and ProtonVPN to block LaLiga stream piracy

• Spanish court orders NordVPN and ProtonVPN to block 16 sites facilitating LaLiga match piracy. • Restrictions apply to a dynamic IP list in Spain, with no appeal rights for VPNs.

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 1 min · 176 words

Supply Chain Attack Embeds Malware in Android Devices

• Keenadu downloads payloads that hijack browser searches, commit ad fraud, and execute other actions without user knowledge.

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 1 min · 105 words

Poland Energy Survives Attack on Wind, Solar Infrastructure

• Russia-aligned groups are probable culprits behind the wiper attacks against renewable energy farms, a manufacturer, and a heating and power plant.

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 1 min · 113 words
Flaws in popular VSCode extensions expose developers to attacks

Flaws in popular VSCode extensions expose developers to attacks

• Flaws in popular VSCode extensions expose developers to attacks February 17, 2026 04:27 PM 0 Vulnerabilities with high to critical severity ratings affecting popular Visual Studi

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 2 min · 392 words

RMM Abuse Explodes as Hackers Ditch Malware

• RMM tools are increasingly used as primary attack vectors, replacing traditional malware. • Attackers leverage RMM’s remote access to maintain stealth and persistence. • RMM’s bu

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 1 min · 166 words

ClickFix Attacks Abuses DNS Lookup Command to Deliver ModeloRAT

• ClickFix campaigns have adapted to the latest defenses with a new technique to trick users into infecting their own machines with malware.

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 1 min · 133 words
Critical Vulnerabilities in Ivanti EPMM Exploited

Critical Vulnerabilities in Ivanti EPMM Exploited

• Executive Summary Two critical zero-day vulnerabilities (CVE-2026-1281 and CVE-2026-1340) affecting Ivanti Endpoint Manager Mobile (EPMM) are being actively exploited in the wild

Cybersecurity · February 17, 2026 (updated February 25, 2026) · 2 min · 300 words
Resilience in the AI era: Google at MSC 2026

Resilience in the AI era: Google at MSC 2026

• Google highlighted MSC 2026’s focus on integrated security amid multi-front cyber threats. • AI-driven attacks now automate reconnaissance, phishing, and supply‑chain sabotage. •

Big Tech · February 17, 2026 (updated February 24, 2026) · 1 min · 172 words
Webinar: How Modern SOC Teams Use AI and Context to Investigate Cloud Breaches Faster

Webinar: How Modern SOC Teams Use AI and Context to Investigate Cloud Breaches Faster

• Cloud attacks outpace traditional incident response, infrastructure vanishes in minutes. • Manual log stitching gives attackers advantage; automated, context-aware forensics need

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 2 min · 262 words
Notepad++ boosts update security with 'double-lock' mechanism

Notepad++ boosts update security with 'double-lock' mechanism

• Notepad++ introduces a double‑lock update system, verifying signed installers from GitHub and XML from its domain. • The new design eliminates DLL side‑loading by removing libcur

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 1 min · 188 words
Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies

Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies

• AI assistants like Copilot and Grok can be hijacked as stealthy C2 proxies, blending into legitimate traffic. • Check Point researchers demonstrated the technique using anonymous

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 2 min · 283 words
Unify now or pay later: New research exposes the operational cost of a fragmented SOC

Unify now or pay later: New research exposes the operational cost of a fragmented SOC

• Share Link copied to clipboard! • Content types Industry trends Topics AI and agents Defending against advanced tactics Security management Security operations SIEM and XDR Secur

Cybersecurity · February 17, 2026 (updated February 25, 2026) · 2 min · 295 words
Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates

Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates

• Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates A new Android backdoor that’s embedded deep into the device firmware can silently harvest data and remote

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 2 min · 330 words
VulnCheck Raises $25 Million in Series B Funding to Scale Vulnerability Intelligence

VulnCheck Raises $25 Million in Series B Funding to Scale Vulnerability Intelligence

• Vulnerability intelligence company VulnCheck announced on Tuesday that it has raised $25 million to meet demand for its solutions.The Series B funding round, which brings the tot

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 2 min · 371 words
Microsoft Teams outage affects users in United States, Europe

Microsoft Teams outage affects users in United States, Europe

• Microsoft Teams experiencing widespread outage across US and Europe, disrupting meetings and chat functionality. • Users report delays and failures when sending or receiving inli

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 1 min · 187 words
What 5 Million Apps Revealed About Secrets in JavaScript

What 5 Million Apps Revealed About Secrets in JavaScript

• What 5 Million Apps Revealed About Secrets in JavaScript February 17, 2026 09:40 AM 0 Leaked API keys are nothing new, but the scale of the problem in front-end code has been lar

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 2 min · 243 words
New Keenadu backdoor found in Android firmware, Google Play apps

New Keenadu backdoor found in Android firmware, Google Play apps

• Keenadu: sophisticated Android malware embedded in firmware across multiple device brands. • Distributes via OTA firmware, system apps, unofficial sources, and Google Play apps.

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 1 min · 186 words
API Threats Grow in Scale as AI Expands the Blast Radius

API Threats Grow in Scale as AI Expands the Blast Radius

• Application Programming Interfaces (APIs) remain an attacker-favored exploit route. • Aggressors continuously target common failures in identity, access control and exposed inter

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 2 min · 228 words
Cyber Insights 2026: The Ongoing Fight to Secure Industrial Control Systems

Cyber Insights 2026: The Ongoing Fight to Secure Industrial Control Systems

• SecurityWeek’s Cyber Insights 2026 examines expert opinions on the expected evolution of more than a dozen areas of cybersecurity interest over the next 12 months. • We spoke to

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 2 min · 269 words
Man Linked to Phobos Ransomware Arrested in Poland

Man Linked to Phobos Ransomware Arrested in Poland

• A 47-year-old man arrested by police in Poland for allegedly being involved in cybercriminal activities has been linked to the Phobos ransomware operation.According to Poland’s C

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 2 min · 360 words
SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer

SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer

• SmartLoader uses a trojanized Oura MCP server to deliver the StealC infostealer. • Threat actors cloned legitimate Oura MCP, creating fake forks to build credibility. • StealC st

Cybersecurity · February 17, 2026 (updated February 24, 2026) · 2 min · 266 words