CVE-2025-52691, CVE-2025-68947, CVE-2026-1281, CVE-2026-1340, CVE-2026-21248, CVE-2026-21256, CVE-2026-21510, CVE-2026-21513, CVE-2026-21514, CVE-2026-21516, CVE-2026-21519, CVE-2026-21523, CVE-2026-21525, CVE-2026-21531, CVE-2026-21533, CVE-2026-21537, CVE-2026-23760, CVE-2026-24300, CVE-2026-24423
Get tomorrow's brief in your inbox
Collected: 2026-02-10 Generated by: Claude Code (Opus 4.6)
Microsoft Patch Tuesday: 6 Actively Exploited Zero-Days (CISA KEV)
Microsoft released patches for 59 vulnerabilities, including six zero-days under active exploitation, all added to the CISA KEV catalog today. Three were publicly disclosed before the patch, meaning exploit details were already circulating.
Highest severity zero-days (CVSS 8.8): - CVE-2026-21510 (Windows Shell) - Single-click bypass of SmartScreen and Shell security prompts. Attacker-controlled content executes without warning. Affects all supported Windows versions. Functional exploit techniques already exist for phishing via crafted links and .lnk files. - CVE-2026-21513 (MSHTML/Internet Explorer engine) - Security feature bypass via malicious HTML or .lnk files leading to code execution. Still relevant because legacy MSHTML is used by Windows components beyond IE.
Additional zero-days (CVSS 7.8): - CVE-2026-21514 (Microsoft Word) - Bypasses OLE mitigations, allowing access to COM/OLE controls via malicious Office file. Preview Pane is not an attack vector. - CVE-2026-21519 (Desktop Window Manager) - Type confusion leading to SYSTEM privileges. Second consecutive month with a DWM zero-day, suggesting the January patch was incomplete. - CVE-2026-21533 (Windows Remote Desktop Services) - Elevation of privilege to SYSTEM via improper privilege management.
Lower severity zero-day (CVSS 6.2): - CVE-2026-21525 (Windows Remote Access Connection Manager) - Null pointer dereference causing denial of service. Affects VPN connections to corporate networks.
Two critical-rated vulnerabilities (CVSS 9.8): - CVE-2026-21531 (Azure SDK) and CVE-2026-24300 (Azure Front Door) - Already patched server-side by Microsoft.
Action: Deploy February Patch Tuesday updates immediately. Prioritize CVE-2026-21510 and CVE-2026-21513 first as they require only user interaction for exploitation and are ideal for phishing campaigns. Test updates via askwoody.com before broad rollout.
Windows Update KBs: Windows 11 25H2/24H2: KB5077181, Windows 11 23H2: KB5075941, Windows 10 ESU: KB5075912.
Sources: Cyberscoop, BleepingComputer, The Register, Talos, Krebs, CISA KEV, SecurityWeek, SANS ISC, Dark Reading
Reported by 9+ sources. This is the top story of the day.
Ivanti EPMM Zero-Day Exploitation Hits European Government Agencies
CVE-2026-1281 and CVE-2026-1340 (CVSS 9.8 each) in Ivanti Endpoint Manager Mobile (EPMM) were exploited as zero-days to breach the Dutch Data Protection Authority (AP), the Dutch Council for the Judiciary, the European Commission, and Finland's Valtori (affecting up to 50,000 government employees). Attackers accessed employee names, work emails, phone numbers, and device details. Ivanti patched both flaws on January 29; exploitation was detected the same day.
The management system did not permanently delete removed data, only marked it as deleted, so historical data from all organizations that ever used the service was also exposed. WatchTowr CEO Benjamin Harris described the attacks as "the work of a highly skilled, well-resourced actor executing a precision campaign."
Action: If running Ivanti EPMM, patch immediately. Verify no unauthorized access occurred between January 29 and your patch date. Audit MDM data retention policies.
Source: The Hacker News
Warlock (Storm-2603) Ransomware Breaches SmarterTools via Unpatched SmarterMail
The Warlock ransomware group breached SmarterTools' internal network on January 29 by exploiting an unpatched SmarterMail VM that an employee had set up without the security team's knowledge. After initial access, attackers waited several days before taking over the Active Directory server, creating new users, and deploying Velociraptor (a forensics tool repurposed for persistence) and the ransomware locker. 12 Windows servers and a QC data center were encrypted. Hosted SmarterTrack customers were also affected.
Three critical SmarterMail CVEs are under active exploitation: - CVE-2025-52691 (CVSS 10.0) - Details not disclosed - CVE-2026-23760 (CVSS 9.3) - Authentication bypass allowing admin password reset via crafted HTTP request - CVE-2026-24423 (CVSS 9.3) - Unauthenticated RCE via ConnectToHub API. CISA confirmed exploitation in ransomware attacks.
The attack chain: bypass authentication via CVE-2026-23760, use SmarterMail's built-in Volume Mount feature for system control, install Velociraptor via malicious MSI from Supabase, then deploy ransomware.
Action: If running SmarterMail, update to build 9511 immediately. Audit for unknown or "shadow" VMs running older versions. SmarterMail instances should not be internet-facing without hardening.
Source: The Hacker News
Reynolds Ransomware Embeds BYOVD Driver to Disable EDR
A new ransomware family called Reynolds bundles a vulnerable NsecSoft NSecKrnl driver (CVE-2025-68947, CVSS 5.7) directly inside the ransomware payload rather than deploying it as a separate pre-attack tool. This BYOVD (Bring Your Own Vulnerable Driver) approach terminates EDR processes from Avast, CrowdStrike Falcon, Cortex XDR, Sophos/HitmanPro, and Symantec before encrypting. The Silver Fox threat actor previously used the same driver to deploy ValleyRAT.
Bundling the defense evasion component with the payload is quieter, with no separate file drop on the network. A suspicious side-loaded loader was observed on victim networks weeks before ransomware deployment, and attackers also deployed GotoHTTP for persistent remote access.
Action: Ensure vulnerable driver blocklist policies are enforced via WDAC or HVCI. Monitor for NSecKrnl driver loading. Block GotoHTTP remote access tool if not in use.
Source: The Hacker News
GitHub Copilot / IDE Command Injection via Prompt Injection
Multiple RCE vulnerabilities in GitHub Copilot affect VS Code, Visual Studio, and JetBrains IDEs: CVE-2026-21516, CVE-2026-21523, CVE-2026-21256. The flaws stem from command injection triggered by prompt injection, where a malicious prompt tricks the AI agent into executing code or commands. Developers with access to API keys and cloud infrastructure credentials are high-value targets.
Action: Update VS Code, Visual Studio, and JetBrains IDE plugins. Apply least-privilege principles to AI agent integrations and review which systems have access to AI tools.
Adobe Patch Tuesday: 44 Vulnerabilities in Creative Apps
Adobe patched 44 vulnerabilities across its creative application suite, including several critical flaws enabling arbitrary code execution.
Action: Update Adobe Creative Cloud applications. Critical for environments where designers open externally-sourced files.
Source: SecurityWeek
Microsoft Defender for Endpoint Linux RCE (CVE-2026-21537)
Code injection vulnerability in Microsoft Defender for Linux allows unauthenticated attackers to execute code over an adjacent network.
Action: Verify Defender for Linux is updated on any Linux servers in your environment.
Source: MSRC
Windows Hyper-V Local Code Execution (CVE-2026-21248)
Heap-based buffer overflow in Hyper-V allows authenticated local code execution.
Action: Included in February Patch Tuesday. Prioritize on Hyper-V hosts.
Source: MSRC
Secure Boot Certificates Expiring June 2026
Microsoft has begun rolling out replacement Secure Boot certificates via monthly Windows updates. The original 2011 certificates expire in late June 2026. Devices that fail to update before expiration will continue to function but enter a "degraded security state" where new boot-level vulnerability mitigations cannot be installed. Over time, newer OS versions, firmware, and Secure Boot-dependent software may fail to load.
Windows 10 (without ESU) and older will not receive new certificates. Many PCs manufactured since 2024 already have updated certificates. Some devices may need firmware updates from OEMs first.
Action: Ensure Windows Update is delivering February patches to all managed endpoints. Verify Secure Boot certificate status. Check OEM support pages for firmware updates on older hardware. Plan Windows 10 migrations before the June deadline compounds the EOL risk. IT admins can deploy certificates via registry keys, Group Policy, or WinCS.
Sources: BleepingComputer, Ars Technica
Microsoft 365 Admin Center Outage (North America)
The M365 admin center and M365 app experienced degraded functionality for North American users. Admins could not raise support tickets or access the portal. Microsoft is investigating CPU utilization levels as a potential root cause. This follows similar outages in January 2025 and July 2025.
Action: No customer action required. Be aware that support ticket creation via admin center is unavailable during the outage. Use alternate support channels if needed.
Source: BleepingComputer
Picus Red Report 2026: Ransomware Shifting to Stealth and Persistence
Analysis of 1.1 million malicious files shows a strategic pivot in attacker behavior. Data Encrypted for Impact (T1486) dropped 38% year-over-year (21% to 12.9%). Credential theft from password stores (T1555) now appears in 25% of attacks. Eight of the top ten ATT&CK techniques prioritize evasion and persistence over disruption. Attackers are optimizing for maximum dwell time rather than immediate impact, using data extortion instead of encryption.
Takeaway: Traditional ransomware detection focused on encryption behavior is increasingly insufficient. Credential monitoring, identity protection, and detection of persistence mechanisms should be prioritized alongside encryption-focused detections.
Source: The Hacker News
Today is dominated by Microsoft's February Patch Tuesday with six actively exploited zero-days, the highest this year and matching last March's record. The common thread across CVE-2026-21510, -21513, and -21514 is security feature bypass: attackers are systematically defeating SmartScreen, Mark of the Web, and OLE protections that users rely on to block malicious files. Combined with the Ivanti EPMM zero-days hitting European governments and the Warlock ransomware campaign leveraging SmarterMail auth bypasses, attackers are consistently targeting trust boundaries (authentication, security prompts, MDM) rather than exploiting memory corruption. Patch immediately and verify that shadow IT instances of email servers and MDM platforms are accounted for.
Carolina Clear Tech, LLC - carolinacleartech.com