Cyber Incidents Digest — 2026-02-19

Daily Cyber Incidents Digest — 2026-02-19

Adidas investigates third-party data breach after criminals claim they pwned the sportswear giant

Published: 2026-02-19 01:00 UTC
Source: https://go.theregister.com/feed/www.theregister.com/2026/02/18/adidas_investigates_thirdparty_data_breach/

‘Potential data protection incident’ at an ‘independent licensing partner,’ we’re told Adidas has confirmed it is investigating a third-party breach at one of its partner companies after digital thieves claimed they stole information and technical data from the German sportswear giant.…

Tags: data breach

ShinyHunters allegedly drove off with 1.7M CarGurus records

Published: 2026-02-19 01:00 UTC
Source: https://go.theregister.com/feed/www.theregister.com/2026/02/18/shinyhunters_cargurus_breach/

Latest in a rash of grab-and-leak data incidents CarGurus allegedly suffered a data breach with 1.7 million corporate records stolen, according to a notorious cybercrime crew that posted the online vehicle marketplace on its leak site on Wednesday.…

Tags: cybercrime, data breach

Fraudster hacked hotel system, paid 1 cent for luxury rooms, Spanish cops say

Published: 2026-02-19 01:00 UTC
Source: https://go.theregister.com/feed/www.theregister.com/2026/02/18/fraudster_hotel_hack_one_cent_luxury_room/

‘First time we have detected a crime using this method,’ cops say Spanish police arrested a hacker who allegedly manipulated a hotel booking website, allowing him to pay one cent for luxury hotel stays. He also raided the mini-bars and didn’t settle some of those tabs, police say.…

Tags: cybersecurity

Deutsche Bahn back on track after DDoS yanks the brakes

Published: 2026-02-19 01:00 UTC
Source: https://go.theregister.com/feed/www.theregister.com/2026/02/18/deutsche_bahn_ddos/

National rail bookings and timetables disrupted for nearly 24 hours If you wanted to book a train trip in Germany recently, you would have been out of luck. The country’s national rail company says that its services were disrupted for hours because of a cyberattack.…

Tags: ddos

Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist’s Phone in Police Custody

Published: 2026-02-19 01:00 UTC
Source: https://thehackernews.com/2026/02/citizen-lab-finds-cellebrite-tool-used.html

New research from the Citizen Lab has found signs that Kenyan authorities used a commercial forensic extraction tool manufactured by Israeli company Cellebrite to break into a prominent dissident’s phone, making it the latest case of abuse of the technology targeting civil society.
The interdisciplinary research unit at the University of Toronto’s Munk School of Global Affairs & Public

Tags: cybersecurity

Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution

Published: 2026-02-19 01:00 UTC
Source: https://thehackernews.com/2026/02/grandstream-gxp1600-voip-phones-exposed.html

Cybersecurity researchers have disclosed a critical security flaw in the Grandstream GXP1600 series of VoIP phones that could allow an attacker to seize control of susceptible devices.
The vulnerability, tracked as CVE-2026-2329, carries a CVSS score of 9.3 out of a maximum of 10.0. It has been described as a case of unauthenticated stack-based buffer overflow that could result in remote code

Tags: vulnerability

Critical Flaws Found in Four VS Code Extensions with Over 125 Million Installs

Published: 2026-02-19 01:00 UTC
Source: https://thehackernews.com/2026/02/critical-flaws-found-in-four-vs-code.html

Cybersecurity researchers have disclosed multiple security vulnerabilities in four popular Microsoft Visual Studio Code (VS Code) extensions that, if successfully exploited, could allow threat actors to steal local files and execute code remotely.
The extensions, which have been collectively installed more than 125 million times, are Live Server, Code Runner, Markdown Preview Enhanced, and

Tags: cybercrime, vulnerability

Cybersecurity Tech Predictions for 2026: Operating in a World of Permanent Instability

Published: 2026-02-19 01:00 UTC
Source: https://thehackernews.com/2026/02/cybersecurity-tech-predictions-for-2026.html

In 2025, navigating the digital seas still felt like a matter of direction. Organizations charted routes, watched the horizon, and adjusted course to reach safe harbors of resilience, trust, and compliance.
In 2026, the seas are no longer calm between storms. Cybersecurity now unfolds in a state of continuous atmospheric instability: AI-driven threats that adapt in real time, expanding

Tags: espionage

Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited Since Mid-2024

Published: 2026-02-19 01:00 UTC
Source: https://thehackernews.com/2026/02/dell-recoverpoint-for-vms-zero-day-cve.html

A maximum severity security vulnerability in Dell RecoverPoint for Virtual Machines has been exploited as a zero-day by a suspected China-nexus threat cluster dubbed UNC6201 since mid-2024, according to a new report from Google Mandiant and Google Threat Intelligence Group (GTIG).
The activity involves the exploitation of CVE-2026-22769 (CVSS score: 10.0), a case of hard-coded credentials

Tags: vulnerability

3 Ways to Start Your Intelligent Workflow Program

Published: 2026-02-19 01:00 UTC
Source: https://thehackernews.com/2026/02/3-ways-to-start-your-intelligent.html

Security, IT, and engineering teams today are under relentless pressure to accelerate outcomes, cut operational drag, and unlock the full potential of AI and automation. But simply investing in tools isn’t enough. 88% of AI proofs-of-concept never make it to production, even though 70% of workers cite freeing time for high-value work as the primary AI automation motivation. Real impact comes

Tags: cybersecurity

Notepad++ Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware

Published: 2026-02-19 01:00 UTC
Source: https://thehackernews.com/2026/02/notepad-fixes-hijacked-update-mechanism.html

Notepad++ has released a security fix to plug gaps that were exploited by an advanced threat actor from China to hijack the software update mechanism to selectively deliver malware to targets of interest.
The version 8.9.2 update incorporates what maintainer Don Ho calls a “double lock” design that aims to make the update process “robust and effectively unexploitable.” This includes verification

Tags: malware, cybercrime, vulnerability, patch

CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV Update

Published: 2026-02-19 01:00 UTC
Source: https://thehackernews.com/2026/02/cisa-flags-four-security-flaws-under.html

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.
The list of vulnerabilities is as follows –

CVE-2026-2441 (CVSS score: 8.8) – A use-after-free vulnerability in Google Chrome that could allow a remote attacker to potentially exploit heap

Tags: vulnerability, patch

Critical infra Honeywell CCTVs vulnerable to auth bypass flaw

Published: 2026-02-19 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/critical-infra-honeywell-cctvs-vulnerable-to-auth-bypass-flaw/

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a critical vulnerability in multiple Honeywell CCTV products that allows unauthorized access to feeds or account hijacking. […]

Tags: vulnerability

AI platforms can be abused for stealthy malware communication

Published: 2026-02-19 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/ai-platforms-can-be-abused-for-stealthy-malware-communication/

AI assistants like Grok and Microsoft Copilot with web browsing and URL-fetching capabilities can be abused to intermediate command-and-control (C2) activity. […]

Tags: malware

Telegram channels expose rapid weaponization of SmarterMail flaws

Published: 2026-02-19 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/telegram-channels-expose-rapid-weaponization-of-smartermail-flaws/

Underground Telegram channels shared SmarterMail exploit PoCs and stolen admin credentials within days of disclosure. Flare explains how monitoring these communities reveals rapid weaponization of CVE-2026-24423 and CVE-2026-23760 tied to ransomware activity. […]

Tags: ransomware, vulnerability

Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages

Published: 2026-02-19 01:00 UTC
Source: https://www.bleepingcomputer.com/news/microsoft/microsoft-anti-phishing-rules-mistakenly-blocked-emails-teams-messages/

Microsoft says an Exchange Online issue that mistakenly quarantined legitimate emails last week was triggered by faulty heuristic detection rules designed to block credential phishing campaigns. […]

Tags: phishing

Data breach at fintech firm Figure affects nearly 1 million accounts

Published: 2026-02-19 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts/

Hackers have stolen the personal and contact information of nearly 1 million accounts after breaching the systems of Figure Technology Solutions, a self-described blockchain-native financial technology company. […]

Tags: data breach

Microsoft says bug causes Copilot to summarize confidential emails

Published: 2026-02-19 01:00 UTC
Source: https://www.bleepingcomputer.com/news/microsoft/microsoft-says-bug-causes-copilot-to-summarize-confidential-emails/

Microsoft says a Microsoft 365 Copilot bug has been causing the AI assistant to summarize confidential emails since late January, bypassing data loss prevention (DLP) policies that organizations rely on to protect sensitive information. […]

Tags: cybersecurity

Glendale man gets 5 years in prison for role in darknet drug ring

Published: 2026-02-19 01:00 UTC
Source: https://www.bleepingcomputer.com/news/security/glendale-man-gets-5-years-in-prison-for-role-in-darknet-drug-trafficking-operation/

​A Glendale man was sentenced to nearly five years in federal prison for his role in a darknet drug trafficking operation that sold cocaine, methamphetamine, MDMA, and ketamine to customers across the United States. […]

Tags: cybersecurity

New Keenadu Android Malware Found on Thousands of Devices

Published: 2026-02-19 01:00 UTC
Source: https://www.securityweek.com/new-keenadu-android-malware-found-on-thousands-of-devices/

The malware has been preinstalled on many devices but it has also been distributed through Google Play and other app stores.
The post New Keenadu Android Malware Found on Thousands of Devices appeared first on SecurityWeek.

Tags: malware

Cogent Security Raises $42 Million for AI-Driven Vulnerability Management

Published: 2026-02-19 01:00 UTC
Source: https://www.securityweek.com/cogent-security-raises-42-million-for-ai-driven-vulnerability-management/

The Series A funding round, led by Bain Capital, brings the total raised by Cogent to $53 million.
The post Cogent Security Raises $42 Million for AI-Driven Vulnerability Management appeared first on SecurityWeek.

Tags: vulnerability

Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration

Published: 2026-02-19 01:00 UTC
Source: https://www.securityweek.com/vulnerabilities-in-popular-pdf-platforms-allowed-account-takeover-data-exfiltration/

Novee researchers discovered 16 vulnerabilities in Foxit and Apryse PDF tools that could have been exploited via malicious documents or URLs.
The post Vulnerabilities in Popular PDF Platforms Allowed Account Takeover, Data Exfiltration appeared first on SecurityWeek.

Tags: vulnerability

CISA: Hackers Exploiting Vulnerability in Product of Taiwan Security Firm TeamT5

Published: 2026-02-19 01:00 UTC
Source: https://www.securityweek.com/cisa-hackers-exploiting-vulnerability-in-product-of-taiwan-security-firm-teamt5/

The vulnerability added to CISA’s KEV catalog affects ThreatSonar Anti-Ransomware and it was patched in 2024.
The post CISA: Hackers Exploiting Vulnerability in Product of Taiwan Security Firm TeamT5 appeared first on SecurityWeek.

Tags: ransomware, vulnerability, patch

Palo Alto Networks to Acquire Koi in Reported $400 Million Transaction

Published: 2026-02-19 01:00 UTC
Source: https://www.securityweek.com/palo-alto-networks-to-acquire-koi-in-reported-400-million-transaction/

Koi has developed an endpoint security solution that Palo Alto will use to enhance its products.
The post Palo Alto Networks to Acquire Koi in Reported $400 Million Transaction appeared first on SecurityWeek.

Tags: cybersecurity

Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group

Published: 2026-02-19 01:00 UTC
Source: https://www.securityweek.com/dell-recoverpoint-zero-day-exploited-by-chinese-cyberespionage-group/

GTIG and Mandiant said the zero-day tracked as CVE-2026-22769 has been exploited by UNC6201 since at least 2024.
The post Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group appeared first on SecurityWeek.

Tags: espionage, vulnerability

Scam Abuses Gemini Chatbots to Convince People to Buy Fake Crypto

Published: 2026-02-19 01:00 UTC
Source: https://www.darkreading.com/endpoint-security/scam-abuses-gemini-chatbots-convince-people-buy-fake-crypto

A convincing presale site for phony “Google Coin” features an AI assistant that engages victims with a slick sales pitch, funneling payment to attackers.

Tags: cybersecurity

Critical Grandstream VoIP Bug Highlights SMB Security Blind Spot

Published: 2026-02-19 01:00 UTC
Source: https://www.darkreading.com/threat-intelligence/grandstream-bug-voip-security-blind-spot

CVE-2026-2329 allows unauthenticated root-level access to SMB phone infrastructure, so attackers can intercept calls, commit toll fraud, and impersonate users.

Tags: vulnerability

Dell’s Hard-Coded Flaw: A Nation-State Goldmine

Published: 2026-02-19 01:00 UTC
Source: https://www.darkreading.com/application-security/dells-hard-coded-flaw-a-nation-state-goldmine

A China-related attacker has exploited the vendor flaw since mid-2024, allowing it to move laterally, maintain persistent access, and deploy malware.

Tags: malware, vulnerability

A CISO’s Playbook for Defending Data Assets Against AI Scraping

Published: 2026-02-19 01:00 UTC
Source: https://www.darkreading.com/cyber-risk/ciso-playbook-defending-data-assets-against-ai-scraping

Discover a strategic approach to govern scraping risks, balance security with business growth, and safeguard intellectual capital from automated data harvesting.

Tags: cybersecurity

This post was generated automatically from public sources. Verify directly with linked sources before taking action.

Scroll to Top