Daily Cyber Incidents Digest — 2026-02-18
China-linked snoops have been exploiting Dell 0-day since mid-2024, using ‘ghost NICs’ to avoid detection
Published: 2026-02-18 01:00 UTC
Source: https://go.theregister.com/feed/www.theregister.com/2026/02/18/dell_0day_brickstorm_campaign/
Full scale of infections remains ‘unknown’ China-linked attackers exploited a maximum-severity hardcoded-credential bug in Dell RecoverPoint for Virtual Machines as a zero-day since at least mid-2024. It’s all part of a long-running effort to backdoor infected machines for long-term access, according to Google’s Mandiant incident response team.…
Tags: vulnerability
China remains embedded in US energy networks ‘for the purpose of taking it down’
Published: 2026-02-18 01:00 UTC
Source: https://go.theregister.com/feed/www.theregister.com/2026/02/17/volt_typhoon_dragos/
Plus 3 new goon squads targeted critical infrastructure last year Three new threat groups began targeting critical infrastructure last year, while a well-known Beijing-backed crew – Volt Typhoon – continued to compromise cellular gateways and routers, and then break into US electric, oil, and gas companies in 2025, according to Dragos’ annual threat report published on Tuesday.…
Tags: cybersecurity
Polish cops nab 47-year-old man in Phobos ransomware raid
Published: 2026-02-18 01:00 UTC
Source: https://go.theregister.com/feed/www.theregister.com/2026/02/17/poland_phobos_ransomware_arrest/
Police say seized kit contained logins, passwords, and server IP addresses Polish police have arrested and charged a man over ties to the Phobos ransomware group following a property raid.…
Tags: ransomware
Webinar: How Modern SOC Teams Use AI and Context to Investigate Cloud Breaches Faster
Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/cloud-forensics-webinar-learn-how-ai.html
Cloud attacks move fast — faster than most incident response teams.
In data centers, investigations had time. Teams could collect disk images, review logs, and build timelines over days. In the cloud, infrastructure is short-lived. A compromised instance can disappear in minutes. Identities rotate. Logs expire. Evidence can vanish before analysis even begins.
Cloud forensics is fundamentally
Tags: cybersecurity
Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies
Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/researchers-show-copilot-and-grok-can.html
Cybersecurity researchers have disclosed that artificial intelligence (AI) assistants that support web browsing or URL fetching capabilities can be turned into stealthy command-and-control (C2) relays, a technique that could allow attackers to blend into legitimate enterprise communications and evade detection.
The attack method, which has been demonstrated against Microsoft Copilot and xAI Grok
Tags: malware
Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates
Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/keenadu-firmware-backdoor-infects.html
A new Android backdoor that’s embedded deep into the device firmware can silently harvest data and remotely control its behavior, according to new findings from Kaspersky.
The Russian cybersecurity vendor said it discovered the backdoor, dubbed Keenadu, in the firmware of devices associated with various brands, including Alldocube, with the compromise occurring during the firmware build phase.
Tags: patch
SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer
Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/smartloader-attack-uses-trojanized-oura.html
Cybersecurity researchers have disclosed details of a new SmartLoader campaign that involves distributing a trojanized version of a Model Context Protocol (MCP) server associated with Oura Health to deliver an information stealer known as StealC.
“The threat actors cloned a legitimate Oura MCP Server – a tool that connects AI assistants to Oura Ring health data – and built a deceptive
Tags: malware, cybercrime
My Day Getting My Hands Dirty with an NDR System
Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/my-day-getting-my-hands-dirty-with-ndr.html
My objectiveThe role of NDR in SOC workflowsStarting up the NDR systemHow AI complements the human responseWhat else did I try out?What could I see with NDR that I wouldn’t otherwise?Am I ready to be a network security analyst now?
My objective
As someone relatively inexperienced with network threat hunting, I wanted to get some hands-on experience using a network detection and response (
Tags: cybersecurity
Microsoft Finds “Summarize with AI” Prompts Manipulating Chatbot Recommendations
Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/microsoft-finds-summarize-with-ai.html
New research from Microsoft has revealed that legitimate businesses are gaming artificial intelligence (AI) chatbots via the “Summarize with AI” button that’s being increasingly placed on websites in ways that mirror classic search engine poisoning (SEO).
The new AI hijacking technique has been codenamed AI Recommendation Poisoning by the Microsoft Defender Security Research Team. The tech giant
Tags: cybersecurity
Apple Tests End-to-End Encrypted RCS Messaging in iOS 26.4 Developer Beta
Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/apple-tests-end-to-end-encrypted-rcs.html
Apple on Monday released a new developer beta of iOS and iPadOS with support for end-to-end encryption (E2EE) in Rich Communications Services (RCS) messages.
The feature is currently available for testing in iOS and iPadOS 26.4 Beta, and is expected to be shipped to customers in a future update for iOS, iPadOS, macOS, and watchOS.
“End-to-end encryption is in beta and is not available for all
Tags: patch, ransomware
Spain orders NordVPN, ProtonVPN to block LaLiga piracy sites
Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/legal/spain-orders-nordvpn-protonvpn-to-block-laliga-piracy-sites/
A Spanish court has granted precautionary measures against NordVPN and ProtonVPN, ordering the two popular VPN providers to block 16 websites that facilitate piracy of football matches. […]
Tags: cybersecurity
Flaws in popular VSCode extensions expose developers to attacks
Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/
Vulnerabilities with high to critical severity ratings affecting popular Visual Studio Code (VSCode) extensions collectively downloaded more than 128 million times could be exploited to steal local files and execute code remotely. […]
Tags: vulnerability
Chinese hackers exploiting Dell zero-day flaw since mid-2024
Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-dell-zero-day-flaw-since-mid-2024/
A suspected Chinese state-backed hacking group has been quietly exploiting a critical Dell security flaw in zero-day attacks that started in mid-2024. […]
Tags: vulnerability, cybercrime
Notepad++ boosts update security with ‘double-lock’ mechanism
Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/notepad-plus-plus-boosts-update-security-with-double-lock-mechanism/
Notepad++ has adopted a “double-lock” design for its update mechanism to address recently exploited security gaps that resulted in a supply-chain compromise. […]
Tags: vulnerability, patch
Microsoft Teams outage affects users in United States, Europe
Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outage-affects-users-in-united-states-europe/
Microsoft is working to resolve an ongoing outage affecting Microsoft Teams users, causing delays and preventing some from accessing the service. […]
Tags: cybersecurity
What 5 Million Apps Revealed About Secrets in JavaScript
Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/what-5-million-apps-revealed-about-secrets-in-javascript/
Leaked API keys are nothing new, but the scale of the problem in front-end code has been largely a mystery – until now. Intruder’s research team built a new secrets detection method and scanned 5 million applications specifically looking for secrets hidden in JavaScript bundles. Here’s what we learned. […]
Tags: data breach
New Keenadu backdoor found in Android firmware, Google Play apps
Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/new-keenadu-backdoor-found-in-android-firmware-google-play-apps/
A newly discovered and sophisticated Android malware called Keenadu has been found embedded in firmware from multiple device brands, enabling it to compromise all installed applications and gain unrestricted control over infected devices. […]
Tags: malware
Poland arrests suspect linked to Phobos ransomware operation
Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/poland-arrests-suspect-linked-to-phobos-ransomware-operation/
Polish police have detained a 47-year-old man suspected of ties to the Phobos ransomware group and seized computers and mobile phones containing stolen credentials, credit card numbers, and server access data. […]
Tags: ransomware
Ireland now also investigating X over Grok-made sexual images
Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/ireland-now-also-investigating-x-over-grok-made-sexual-images/
Ireland’s Data Protection Commission (DPC), the country’s data protection authority, has opened a formal investigation into X over the use of the platform’s Grok artificial intelligence tool to generate non-consensual sexual images of real people, including children. […]
Tags: cybersecurity
VulnCheck Raises $25 Million in Series B Funding to Scale Vulnerability Intelligence
Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/vulncheck-raises-25-million-in-series-b-funding-to-scale-vulnerability-intelligence/
The latest funding round was led by Sorenson Capital and brings the total investment to $45 million.
The post VulnCheck Raises $25 Million in Series B Funding to Scale Vulnerability Intelligence appeared first on SecurityWeek.
Tags: vulnerability
Hackers Offer to Sell Millions of Eurail User Records
Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/hackers-offer-to-sell-millions-of-eurail-user-records/
Eurail has confirmed that the stolen data is up for sale, but it’s still trying to determine how many individuals are impacted.
The post Hackers Offer to Sell Millions of Eurail User Records appeared first on SecurityWeek.
Tags: data breach
API Threats Grow in Scale as AI Expands the Blast Radius
Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/api-threats-grow-in-scale-as-ai-expands-the-blast-radius/
New research shows attackers increasingly abusing APIs at machine speed as AI-driven systems widen exposure and amplify impact.
The post API Threats Grow in Scale as AI Expands the Blast Radius appeared first on SecurityWeek.
Tags: cybersecurity
Cyber Insights 2026: The Ongoing Fight to Secure Industrial Control Systems
Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/cyber-insights-2026-the-ongoing-fight-to-secure-industrial-control-systems/
As nation-state actors, ransomware groups, and aging infrastructure collide, organizations must rethink how they defend critical operations through resilience, visibility, and modern security strategies.
The post Cyber Insights 2026: The Ongoing Fight to Secure Industrial Control Systems appeared first on SecurityWeek.
Tags: ransomware
Man Linked to Phobos Ransomware Arrested in Poland
Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/man-linked-to-phobos-ransomware-arrested-in-poland/
Polish police said they found evidence of cybercrime on the 47-year-old suspect’s devices.
The post Man Linked to Phobos Ransomware Arrested in Poland appeared first on SecurityWeek.
Tags: ransomware, cybercrime
3 Threat Groups Started Targeting ICS/OT in 2025: Dragos
Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/3-threat-groups-started-targeting-ics-ot-in-2025-dragos/
Industrial cybersecurity firm Dragos has published its 9th Year in Review OT/ICS Cybersecurity Report.
The post 3 Threat Groups Started Targeting ICS/OT in 2025: Dragos appeared first on SecurityWeek.
Tags: cybersecurity
Password Managers Vulnerable to Vault Compromise Under Malicious Server
Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/password-managers-vulnerable-to-vault-compromise-under-malicious-server/
Researchers at ETH Zurich have tested the security of Bitwarden, LastPass, Dashlane, and 1Password password managers.
The post Password Managers Vulnerable to Vault Compromise Under Malicious Server appeared first on SecurityWeek.
Tags: cybersecurity
Singapore & Its 4 Major Telcos Fend Off Chinese Hackers
Published: 2026-02-18 01:00 UTC
Source: https://www.darkreading.com/cyberattacks-data-breaches/singapore-major-telcos-fend-chinese-hackers
After detecting a zero-day attack, the country’s effective response was attributed to the tight relationship between its government and private industry.
Tags: vulnerability
Supply Chain Attack Embeds Malware in Android Devices
Published: 2026-02-18 01:00 UTC
Source: https://www.darkreading.com/mobile-security/supply-chain-attack-embeds-malware-android-devices
Keenadu downloads payloads that hijack browser searches, commit ad fraud, and execute other actions without user knowledge.
Tags: supply chain, malware
Poland Energy Survives Attack on Wind, Solar Infrastructure
Published: 2026-02-18 01:00 UTC
Source: https://www.darkreading.com/threat-intelligence/poland-energy-attack-wind-solar-infrastructure
Russia-aligned groups are probable culprits behind the wiper attacks against renewable energy farms, a manufacturer, and a heating and power plant.
Tags: cybersecurity
RMM Abuse Explodes as Hackers Ditch Malware
Published: 2026-02-18 01:00 UTC
Source: https://www.darkreading.com/application-security/rmm-abuse-explodes-hackers-ditch-malware
Remote monitoring and management (RMM) software offers hackers multiple benefits, including stealth, persistence, and operational efficiency.
Tags: malware
ClickFix Attacks Abuses DNS Lookup Command to Deliver ModeloRAT
Published: 2026-02-18 01:00 UTC
Source: https://www.darkreading.com/endpoint-security/clickfix-attacks-dns-lookup-command-modelorat
ClickFix campaigns have adapted to the latest defenses with a new technique to trick users into infecting their own machines with malware.
Tags: malware, espionage
Weekly Update 491
Published: 2026-02-18 01:00 UTC
Source: https://www.troyhunt.com/weekly-update-491/
Well, the ESP32 Bluetooth bridge experiment was a complete failure. Not the radios themselves, they’re actually pretty cool, but there’s just no way I could get the Yale locks to be reliably operated by them. At a guess, BLE is a bit too passive to detect
Tags: patch
This post was generated automatically from public sources. Verify directly with linked sources before taking action.