← Carolina Clear Tech

Cyber Threat Brief

2026-02-17

Listen to this brief (5:51)

Download MP3
Show Notes

Show Notes - 2026-02-17

Stories Covered

CVEs Referenced

CVE-2026-26119

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Cyber Threat Brief - 2026-02-17

Today: Microsoft patched CVE-2026-26119, an elevation of privilege flaw in Windows Admin Center caused by improper authentication. ClickFix social engineering campaigns now abuse DNS lookup commands to deliver ModeloRAT. A supply chain attack embeds Keenadu malware directly into Android device firmware at the build phase.

Vulnerability Disclosures

Windows Admin Center Elevation of Privilege (CVE-2026-26119)

Microsoft disclosed CVE-2026-26119, an improper authentication vulnerability in Windows Admin Center that allows an authorized attacker to elevate privileges over a network. No CVSS score or EPSS data is available yet.

Apple Tests End-to-End Encrypted RCS Messaging in iOS 26.4 Developer Beta

Apple released iOS and iPadOS 26.4 beta with end-to-end encryption for RCS messages, built on the MLS protocol via RCS Universal Profile 3.0. E2EE is currently limited to Apple-to-Apple conversations. The beta also enables full Memory Integrity Enforcement (MIE) mode for apps and will make Stolen Device Protection the default for all iPhones, adding biometric authentication and a one-hour delay for sensitive account changes when away from familiar locations.

Business & Infrastructure Threats

Supply Chain Attack Embeds Keenadu Malware in Android Device Firmware

A supply chain attack embeds malware called Keenadu directly into Android device firmware during manufacturing. Once active, Keenadu downloads payloads that hijack browser searches, commit ad fraud, and execute additional actions without user knowledge. Devices compromised at the firmware level cannot be cleaned through standard app removal or factory resets.

ClickFix Attacks Abuse DNS Lookup Commands to Deliver ModeloRAT

ClickFix social engineering campaigns have evolved with a new technique that abuses DNS lookup commands (nslookup) to trick users into infecting their own machines with ModeloRAT. The attack bypasses traditional download-based detection by using a legitimate system utility as the delivery mechanism.

General Security News

Ireland Opens GDPR Investigation into X's Grok AI

Ireland's Data Protection Commission launched a formal GDPR investigation into X over Grok AI's ability to generate non-consensual sexual images of real people, including children. As the lead EU supervisory authority for X, the DPC's findings could result in fines enforceable across all 27 EU member states and three EEA countries. This joins existing investigations by the UK ICO, the European Commission, California AG, UK Ofcom, and French prosecutors who raided X's Paris offices and summoned Elon Musk for April interviews.

Trends & Context

Two themes stand out today: social engineering is getting more creative, and supply chain compromise continues to move deeper into hardware. ClickFix campaigns now weaponize built-in system tools like nslookup rather than relying on traditional malware downloads, making detection harder with standard controls. Keenadu's firmware-level embedding during manufacturing represents the most persistent form of supply chain attack, one that survives factory resets and requires full device replacement.