Cyber Incidents Digest — 2026-02-18

Daily Cyber Incidents Digest — 2026-02-18

China-linked snoops have been exploiting Dell 0-day since mid-2024, using ‘ghost NICs’ to avoid detection

Published: 2026-02-18 01:00 UTC
Source: https://go.theregister.com/feed/www.theregister.com/2026/02/18/dell_0day_brickstorm_campaign/

Full scale of infections remains ‘unknown’ China-linked attackers exploited a maximum-severity hardcoded-credential bug in Dell RecoverPoint for Virtual Machines as a zero-day since at least mid-2024. It’s all part of a long-running effort to backdoor infected machines for long-term access, according to Google’s Mandiant incident response team.…

Tags: vulnerability

China remains embedded in US energy networks ‘for the purpose of taking it down’

Published: 2026-02-18 01:00 UTC
Source: https://go.theregister.com/feed/www.theregister.com/2026/02/17/volt_typhoon_dragos/

Plus 3 new goon squads targeted critical infrastructure last year Three new threat groups began targeting critical infrastructure last year, while a well-known Beijing-backed crew – Volt Typhoon – continued to compromise cellular gateways and routers, and then break into US electric, oil, and gas companies in 2025, according to Dragos’ annual threat report published on Tuesday.…

Tags: cybersecurity

Polish cops nab 47-year-old man in Phobos ransomware raid

Published: 2026-02-18 01:00 UTC
Source: https://go.theregister.com/feed/www.theregister.com/2026/02/17/poland_phobos_ransomware_arrest/

Police say seized kit contained logins, passwords, and server IP addresses Polish police have arrested and charged a man over ties to the Phobos ransomware group following a property raid.…

Tags: ransomware

Webinar: How Modern SOC Teams Use AI and Context to Investigate Cloud Breaches Faster

Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/cloud-forensics-webinar-learn-how-ai.html

Cloud attacks move fast — faster than most incident response teams.
In data centers, investigations had time. Teams could collect disk images, review logs, and build timelines over days. In the cloud, infrastructure is short-lived. A compromised instance can disappear in minutes. Identities rotate. Logs expire. Evidence can vanish before analysis even begins.
Cloud forensics is fundamentally

Tags: cybersecurity

Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies

Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/researchers-show-copilot-and-grok-can.html

Cybersecurity researchers have disclosed that artificial intelligence (AI) assistants that support web browsing or URL fetching capabilities can be turned into stealthy command-and-control (C2) relays, a technique that could allow attackers to blend into legitimate enterprise communications and evade detection.
The attack method, which has been demonstrated against Microsoft Copilot and xAI Grok

Tags: malware

Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates

Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/keenadu-firmware-backdoor-infects.html

A new Android backdoor that’s embedded deep into the device firmware can silently harvest data and remotely control its behavior, according to new findings from Kaspersky.
The Russian cybersecurity vendor said it discovered the backdoor, dubbed Keenadu, in the firmware of devices associated with various brands, including Alldocube, with the compromise occurring during the firmware build phase.

Tags: patch

SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer

Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/smartloader-attack-uses-trojanized-oura.html

Cybersecurity researchers have disclosed details of a new SmartLoader campaign that involves distributing a trojanized version of a Model Context Protocol (MCP) server associated with Oura Health to deliver an information stealer known as StealC.
“The threat actors cloned a legitimate Oura MCP Server – a tool that connects AI assistants to Oura Ring health data – and built a deceptive

Tags: malware, cybercrime

My Day Getting My Hands Dirty with an NDR System

Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/my-day-getting-my-hands-dirty-with-ndr.html

My objectiveThe role of NDR in SOC workflowsStarting up the NDR systemHow AI complements the human responseWhat else did I try out?What could I see with NDR that I wouldn’t otherwise?Am I ready to be a network security analyst now?

My objective
As someone relatively inexperienced with network threat hunting, I wanted to get some hands-on experience using a network detection and response (

Tags: cybersecurity

Microsoft Finds “Summarize with AI” Prompts Manipulating Chatbot Recommendations

Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/microsoft-finds-summarize-with-ai.html

New research from Microsoft has revealed that legitimate businesses are gaming artificial intelligence (AI) chatbots via the “Summarize with AI” button that’s being increasingly placed on websites in ways that mirror classic search engine poisoning (SEO).
The new AI hijacking technique has been codenamed AI Recommendation Poisoning by the Microsoft Defender Security Research Team. The tech giant

Tags: cybersecurity

Apple Tests End-to-End Encrypted RCS Messaging in iOS 26.4 Developer Beta

Published: 2026-02-18 01:00 UTC
Source: https://thehackernews.com/2026/02/apple-tests-end-to-end-encrypted-rcs.html

Apple on Monday released a new developer beta of iOS and iPadOS with support for end-to-end encryption (E2EE) in Rich Communications Services (RCS) messages.
The feature is currently available for testing in iOS and iPadOS 26.4 Beta, and is expected to be shipped to customers in a future update for iOS, iPadOS, macOS, and watchOS.
“End-to-end encryption is in beta and is not available for all

Tags: patch, ransomware

Spain orders NordVPN, ProtonVPN to block LaLiga piracy sites

Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/legal/spain-orders-nordvpn-protonvpn-to-block-laliga-piracy-sites/

A Spanish court has granted precautionary measures against NordVPN and ProtonVPN, ordering the two popular VPN providers to block 16 websites that facilitate piracy of football matches. […]

Tags: cybersecurity

Flaws in popular VSCode extensions expose developers to attacks

Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/

Vulnerabilities with high to critical severity ratings affecting popular Visual Studio Code (VSCode) extensions collectively downloaded more than 128 million times could be exploited to steal local files and execute code remotely. […]

Tags: vulnerability

Chinese hackers exploiting Dell zero-day flaw since mid-2024

Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/chinese-hackers-exploiting-dell-zero-day-flaw-since-mid-2024/

A suspected Chinese state-backed hacking group has been quietly exploiting a critical Dell security flaw in zero-day attacks that started in mid-2024. […]

Tags: vulnerability, cybercrime

Notepad++ boosts update security with ‘double-lock’ mechanism

Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/notepad-plus-plus-boosts-update-security-with-double-lock-mechanism/

Notepad++ has adopted a “double-lock” design for its update mechanism to address recently exploited security gaps that resulted in a supply-chain compromise. […]

Tags: vulnerability, patch

Microsoft Teams outage affects users in United States, Europe

Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outage-affects-users-in-united-states-europe/

​Microsoft is working to resolve an ongoing outage affecting Microsoft Teams users, causing delays and preventing some from accessing the service. […]

Tags: cybersecurity

What 5 Million Apps Revealed About Secrets in JavaScript

Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/what-5-million-apps-revealed-about-secrets-in-javascript/

Leaked API keys are nothing new, but the scale of the problem in front-end code has been largely a mystery – until now. Intruder’s research team built a new secrets detection method and scanned 5 million applications specifically looking for secrets hidden in JavaScript bundles. Here’s what we learned. […]

Tags: data breach

New Keenadu backdoor found in Android firmware, Google Play apps

Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/new-keenadu-backdoor-found-in-android-firmware-google-play-apps/

A newly discovered and sophisticated Android malware called Keenadu has been found embedded in firmware from multiple device brands, enabling it to compromise all installed applications and gain unrestricted control over infected devices. […]

Tags: malware

Poland arrests suspect linked to Phobos ransomware operation

Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/poland-arrests-suspect-linked-to-phobos-ransomware-operation/

Polish police have detained a 47-year-old man suspected of ties to the Phobos ransomware group and seized computers and mobile phones containing stolen credentials, credit card numbers, and server access data. […]

Tags: ransomware

Ireland now also investigating X over Grok-made sexual images

Published: 2026-02-18 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/ireland-now-also-investigating-x-over-grok-made-sexual-images/

Ireland’s Data Protection Commission (DPC), the country’s data protection authority, has opened a formal investigation into X over the use of the platform’s Grok artificial intelligence tool to generate non-consensual sexual images of real people, including children. […]

Tags: cybersecurity

VulnCheck Raises $25 Million in Series B Funding to Scale Vulnerability Intelligence

Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/vulncheck-raises-25-million-in-series-b-funding-to-scale-vulnerability-intelligence/

The latest funding round was led by Sorenson Capital and brings the total investment to $45 million.
The post VulnCheck Raises $25 Million in Series B Funding to Scale Vulnerability Intelligence appeared first on SecurityWeek.

Tags: vulnerability

Hackers Offer to Sell Millions of Eurail User Records

Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/hackers-offer-to-sell-millions-of-eurail-user-records/

Eurail has confirmed that the stolen data is up for sale, but it’s still trying to determine how many individuals are impacted.
The post Hackers Offer to Sell Millions of Eurail User Records appeared first on SecurityWeek.

Tags: data breach

API Threats Grow in Scale as AI Expands the Blast Radius

Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/api-threats-grow-in-scale-as-ai-expands-the-blast-radius/

New research shows attackers increasingly abusing APIs at machine speed as AI-driven systems widen exposure and amplify impact.
The post API Threats Grow in Scale as AI Expands the Blast Radius appeared first on SecurityWeek.

Tags: cybersecurity

Cyber Insights 2026: The Ongoing Fight to Secure Industrial Control Systems

Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/cyber-insights-2026-the-ongoing-fight-to-secure-industrial-control-systems/

As nation-state actors, ransomware groups, and aging infrastructure collide, organizations must rethink how they defend critical operations through resilience, visibility, and modern security strategies.
The post Cyber Insights 2026: The Ongoing Fight to Secure Industrial Control Systems appeared first on SecurityWeek.

Tags: ransomware

Man Linked to Phobos Ransomware Arrested in Poland

Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/man-linked-to-phobos-ransomware-arrested-in-poland/

Polish police said they found evidence of cybercrime on the 47-year-old suspect’s devices.
The post Man Linked to Phobos Ransomware Arrested in Poland appeared first on SecurityWeek.

Tags: ransomware, cybercrime

3 Threat Groups Started Targeting ICS/OT in 2025: Dragos

Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/3-threat-groups-started-targeting-ics-ot-in-2025-dragos/

Industrial cybersecurity firm Dragos has published its 9th Year in Review OT/ICS Cybersecurity Report.
The post 3 Threat Groups Started Targeting ICS/OT in 2025: Dragos  appeared first on SecurityWeek.

Tags: cybersecurity

Password Managers Vulnerable to Vault Compromise Under Malicious Server

Published: 2026-02-18 01:00 UTC
Source: https://www.securityweek.com/password-managers-vulnerable-to-vault-compromise-under-malicious-server/

Researchers at ETH Zurich have tested the security of Bitwarden, LastPass, Dashlane, and 1Password password managers.
The post Password Managers Vulnerable to Vault Compromise Under Malicious Server appeared first on SecurityWeek.

Tags: cybersecurity

Singapore & Its 4 Major Telcos Fend Off Chinese Hackers

Published: 2026-02-18 01:00 UTC
Source: https://www.darkreading.com/cyberattacks-data-breaches/singapore-major-telcos-fend-chinese-hackers

After detecting a zero-day attack, the country’s effective response was attributed to the tight relationship between its government and private industry.

Tags: vulnerability

Supply Chain Attack Embeds Malware in Android Devices

Published: 2026-02-18 01:00 UTC
Source: https://www.darkreading.com/mobile-security/supply-chain-attack-embeds-malware-android-devices

Keenadu downloads payloads that hijack browser searches, commit ad fraud, and execute other actions without user knowledge.

Tags: supply chain, malware

Poland Energy Survives Attack on Wind, Solar Infrastructure

Published: 2026-02-18 01:00 UTC
Source: https://www.darkreading.com/threat-intelligence/poland-energy-attack-wind-solar-infrastructure

Russia-aligned groups are probable culprits behind the wiper attacks against renewable energy farms, a manufacturer, and a heating and power plant.

Tags: cybersecurity

RMM Abuse Explodes as Hackers Ditch Malware

Published: 2026-02-18 01:00 UTC
Source: https://www.darkreading.com/application-security/rmm-abuse-explodes-hackers-ditch-malware

Remote monitoring and management (RMM) software offers hackers multiple benefits, including stealth, persistence, and operational efficiency.

Tags: malware

ClickFix Attacks Abuses DNS Lookup Command to Deliver ModeloRAT

Published: 2026-02-18 01:00 UTC
Source: https://www.darkreading.com/endpoint-security/clickfix-attacks-dns-lookup-command-modelorat

ClickFix campaigns have adapted to the latest defenses with a new technique to trick users into infecting their own machines with malware.

Tags: malware, espionage

Weekly Update 491

Published: 2026-02-18 01:00 UTC
Source: https://www.troyhunt.com/weekly-update-491/

Well, the ESP32 Bluetooth bridge experiment was a complete failure. Not the radios themselves, they’re actually pretty cool, but there’s just no way I could get the Yale locks to be reliably operated by them. At a guess, BLE is a bit too passive to detect

Tags: patch

This post was generated automatically from public sources. Verify directly with linked sources before taking action.

Scroll to Top