← Carolina Clear Tech

Cyber Threat Brief

2026-02-16

Listen to this brief (16:10)

Download MP3
Show Notes

Show Notes - 2026-02-16

Stories Covered

CVEs Referenced

CVE-2026-2441

Indicators of Compromise

Domains: 84[.]21.189

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Cyber Threat Brief - February 16, 2026

Generated: 2026-02-16 | Sources: 40 articles from 10 feeds


Today: Google patched Chrome's first zero-day of 2026 (CVE-2026-2441), a use-after-free in CSS handling already exploited in the wild; push browser updates now. ClickFix attacks evolved again with a DNS-based variant using nslookup to stage PowerShell payloads via attacker-controlled nameservers. ShinyHunters leaked 600K Canada Goose customer records, and researchers found Bitwarden, LastPass, and Dashlane all fail their zero-knowledge encryption promises under server compromise scenarios.


Critical Alerts

Google Chrome Zero-Day Actively Exploited (CVE-2026-2441)

Google released an emergency Chrome update to fix CVE-2026-2441, a high-severity (CVSS 8.8) use-after-free in Chrome's CSS handling that allows remote code execution inside the browser sandbox via a crafted HTML page. Attackers were exploiting this vulnerability in the wild before a fix was available. Security researcher Shaheen Fazim reported the flaw on February 11, and Google confirmed active exploitation two days later. EPSS is currently 0.000 (8th percentile), likely lagging behind the confirmed wild exploitation. Fixed versions: 145.0.7632.75 for Windows/Mac, 144.0.7559.75 for Linux.


Vulnerability Disclosures

Windows 11 KB5077181 Fixes Boot Failures from Failed Update Rollbacks

Microsoft resolved a Windows 11 bug that caused commercial devices running 25H2 and 24H2 to fail with "UNMOUNTABLE_BOOT_VOLUME" errors after installing the January 2026 security update KB5074109. The root cause was the December 2025 update failing to install and rolling back improperly, leaving devices in a state where subsequent updates made systems unbootable. The fix shipped in the February 2026 Patch Tuesday update KB5077181. Devices that became unbootable before the fix still require manual remediation. Virtual machines and home editions were not affected.

Password Managers Fail Zero-Knowledge Encryption Promises Under Server Compromise

Researchers from ETH Zurich and USI tested the zero-knowledge encryption claims of Bitwarden, LastPass, and Dashlane using a malicious server model. All three exposed passwords when servers were compromised. Bitwarden was most vulnerable with 12 working attacks (7 leading to password disclosure). LastPass had 7 attacks (3 disclosures), Dashlane had 6 (1 disclosure). Most attacks required only routine user actions: logging in, opening the vault, or syncing data. None of the vendors clearly define the threat model their encryption protects against. The researchers note password managers have received far less academic scrutiny than E2E encrypted messaging apps, despite complex codebases with features like credential sharing and backward-compatibility with older encryption standards.


Ransomware & Extortion

BridgePay Ransomware Attack Disrupts Government Payment Services Nationwide

Payment service provider BridgePay, which processes transactions for local governments and utilities across the US, has been offline since February 6 due to a ransomware attack. Restoration could take at least another week. BridgePay says payment information was not compromised but has not determined the full scope. Some municipalities like Frisco, Texas suspended shutoffs and late fees; others have not offered similar relief.

Fake Ransomware Group 0APT Exposed as Complete Fabrication

GuidePoint Security determined that the ransomware group "0APT," which claimed over 200 victims in a single week, fabricated its entire operation. Claimed victims had names like "Metropolis City Municipal," and high-profile companies listed on the group's leak site found no evidence of intrusion. The scam likely aims to sell fake RaaS tools to other criminals or trick organizations into paying ransoms out of fear.

ShinyHunters Leaks 600K Canada Goose Customer Records

ShinyHunters published a 1.67 GB dataset containing 600,000+ Canada Goose customer records in JSON format, including names, emails, phone numbers, billing/shipping addresses, IP addresses, order histories, partial payment card data (last four digits, BIN in some cases), and device/browser metadata. Canada Goose says it found no evidence of a direct breach of its systems and believes the data relates to past transactions, possibly from a third-party payment processor breach in August 2025. The dataset schema closely resembles e-commerce checkout exports from hosted storefront platforms.

LVMH Brands Fined $25M in South Korea After Scattered Spider/LAPSUS$ Breaches

Dior, Louis Vuitton, and Tiffany were fined $25 million in South Korea after Scattered LAPSUS$ Hunters targeted their Salesforce instances, leading to data breaches. This highlights ongoing risk for organizations relying on SaaS platforms targeted by social engineering groups.


Business & Infrastructure Threats

ClickFix Attack Now Uses DNS Queries for Payload Delivery

Microsoft disclosed a new ClickFix variant that uses nslookup against attacker-controlled DNS servers to retrieve and execute PowerShell payloads. Victims are tricked into running a command via the Windows Run dialog that queries an external nameserver at 84[.]21.189[.]20, parses the DNS NAME response, and pipes it into cmd.exe. The second-stage downloads a ZIP containing a Python runtime and malicious scripts that perform domain reconnaissance and establish persistence via %APPDATA%\WPy64-31401\python\script.vbs and a %STARTUP%\MonitoringService.lnk shortcut. The final payload is ModeloRAT, a remote access trojan. Using DNS as a staging channel lets attackers modify payloads dynamically while blending into normal network traffic. Separately, attackers have begun using shared ChatGPT, Grok, and Claude Artifact pages as ClickFix lure platforms.

260K+ Chrome Users Hit by Fake AI Browser Extensions

Over 30 copycat Chrome extensions impersonating legitimate AI tools tricked more than 260,000 users and bypassed Google's own review process. The extensions steal API keys, emails, and other sensitive data.

Open Source Registries Financially Unable to Implement Basic Security

Alpha-Omega's analysis of major open source registries (PyPI, npm, Crates.io, RubyGems, Maven Central) found all are financially stretched thin. Bandwidth is the top cost (25%), followed by storage (18%), compute (15%), and malware fighting (12%). Registries detected 845,000 malware packages from 2019 to January 2025, with npm absorbing the majority. The median time to remove a malicious package is 39 hours, long enough for worm-style propagation like the Shai-Hulud npm outbreak in September.

Former L3Harris Executive Sold Eight Zero-Day Exploit Kits to Russia

DoJ sentencing memorandum revealed that Peter Williams, former GM of L3Harris's cyber subsidiary Trenchant, sold eight zero-day exploit kits to a broker who regularly supplied the Russian government. Williams faces up to 9 years, $35 million restitution, and deportation to Australia. The DoJ said Williams' actions caused significant harm to US national security and enabled exploitation "against any manner of victim, civilian or military."


General Security News

ZeroDayRAT Mobile Spyware Platform Sold on Telegram

iVerify disclosed a commercial mobile spyware platform called ZeroDayRAT, sold on Telegram with dedicated sales and support channels. It targets Android 5-16 and iOS up to 26. Capabilities include real-time GPS tracking, live camera/microphone streaming, keylogging, SMS/OTP interception (defeating 2FA), account enumeration across Google/WhatsApp/Instagram/Amazon, and cryptocurrency wallet address swapping for financial theft. A bank stealer module targets Apple Pay, Google Pay, PayPal, and regional payment apps. This level of capability was previously limited to nation-state tools.

64-Bit Malware Approaching 50-50 Parity with 32-Bit

SANS ISC analysis of 346,985 PE samples from Malware Bazaar (2020-2026) shows 64-bit malware approaching 50% of samples in the last 30 days, up from 11% overall. 32-bit code historically dominated because it runs on both architectures via WoW64. The shift toward 64-bit indicates threat actors are increasingly targeting modern systems directly and potentially evading 32-bit-focused analysis tools.

Promptware Kill Chain Framework Proposed for LLM Attacks

Researchers proposed a seven-step "promptware kill chain" to categorize attacks against LLM-based systems: Initial Access (prompt injection), Privilege Escalation (jailbreaking), Reconnaissance (context extraction), Persistence (memory poisoning), Execution, Exfiltration, and Impact. The framework highlights that LLMs process all input as undifferentiated tokens with no architectural boundary between trusted instructions and untrusted data.

Android 17 Beta Strengthens Secure-by-Default Privacy and App Security

The latest Android beta continues hardening security and privacy defaults. Organizations deploying Android devices should track these changes for MDM policy alignment.


Trends & Context

ClickFix attacks continue to fragment into specialized variants at speed. DNS-based payload staging via nslookup joins browser JavaScript injection, OAuth abuse, and AI platform lures in the growing ClickFix toolkit. The common thread is tricking users into self-infecting through pasted commands, which bypasses endpoint protection. The password manager research and ZeroDayRAT mobile spyware highlight opposite ends of the same problem: defensive tools have weaker guarantees than marketed, while offensive tools that once required nation-state budgets are now sold commercially on Telegram for anyone to buy. The Chrome zero-day (CVE-2026-2441) is the top action item; push browser updates immediately.