← Carolina Clear Tech

Cyber Threat Brief

2026-02-18

Listen to this brief (11:22)

Download MP3
Show Notes

Show Notes - 2026-02-18

Stories Covered

CVEs Referenced

CVE-2008-0015, CVE-2020-7796, CVE-2023-4911, CVE-2024-21646, CVE-2024-46981, CVE-2024-6345, CVE-2024-7694, CVE-2025-15467, CVE-2026-22769, CVE-2026-2441

Indicators of Compromise

IP Addresses: 6.0.3.1

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Carolina ClearTech Cyber Threat Brief - 2026-02-18

Today: CISA added four CVEs to its KEV catalog today with a March 10 deadline, including an actively exploited Chrome zero-day (CVE-2026-2441) and a 2008-era Windows Video ActiveX buffer overflow (CVE-2008-0015) that downloads the Dogkild worm. A China-nexus group has been quietly exploiting a CVSS 10.0 hard-coded credential flaw in Dell RecoverPoint for VMs since mid-2024, planting BRICKSTORM backdoors across North American targets. Separately, AI-assisted research discovered twelve new OpenSSL zero-days, including a CVSS 9.8 stack buffer overflow in CMS parsing with public exploits already circulating.


Critical Alerts

CISA KEV Update: Four CVEs Added, March 10 Deadline (CVE-2026-2441, CVE-2020-7796, CVE-2008-0015, CVE-2024-7694)

CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog today. CVE-2026-2441 (CVSS 8.8) is a use-after-free in Google Chrome that Google has confirmed is being exploited in the wild via crafted HTML pages. CVE-2020-7796 (CVSS 9.8, EPSS 91%) is an SSRF in Synacor Zimbra Collaboration Suite; GreyNoise tracked roughly 400 IPs actively exploiting it in 2025 across the US, Germany, Singapore, India, Lithuania, and Japan. CVE-2008-0015 (CVSS 8.8, EPSS 88%) is a stack-based buffer overflow in Windows Video ActiveX Control that enables RCE and has been used to deliver the Dogkild worm, which terminates security processes, overwrites the Windows Hosts file to block security vendor sites, and propagates via removable drives. CVE-2024-7694 (CVSS 7.2) is an arbitrary file upload in TeamT5 ThreatSonar Anti-Ransomware versions 3.4.5 and earlier enabling arbitrary command execution on the server. FCEB agencies must remediate all four by March 10, 2026.


Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited by China-Nexus UNC6201 Since Mid-2024

CVE-2026-22769 (CVSS 10.0) is a hard-coded credential flaw affecting Dell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1. An unauthenticated remote attacker with knowledge of the hardcoded "admin" credential for the Apache Tomcat Manager can upload a web shell (named SLAYSTYLE) via /manager/text/deploy, gain root execution, and deploy the BRICKSTORM backdoor or its newer variant GRIMBOLT. GRIMBOLT is a C# backdoor compiled with native AOT to make reverse engineering harder and is designed to blend in with system files. Google Mandiant and GTIG attribute this campaign to UNC6201, assessed to overlap with UNC5221, a known China-nexus group that previously exploited Ivanti edge appliances. Attackers used temporary "Ghost NIC" virtual network interfaces to pivot into internal and SaaS environments and then deleted those interfaces to hinder forensics. Targets have been concentrated in North America.


Vulnerability Disclosures

AI-Discovered OpenSSL Zero-Days: 12 New CVEs Including CVSS 9.8 CMS Parsing Flaw (CVE-2025-15467)

An AI-driven security research system (AISLE) found twelve zero-day vulnerabilities in OpenSSL, disclosed in the January 27, 2026 OpenSSL security release. The most severe is CVE-2025-15467 (CVSS 9.8 critical), a stack buffer overflow in CMS message parsing that is potentially remotely exploitable without valid key material. Public exploits for this flaw have already been developed online. Three of the twelve bugs had been present since 1998-2000, including one inherited from the original SSLeay implementation. This is noteworthy context for threat modeling: AI tooling is now discovering critical bugs in heavily audited, heavily fuzzed libraries at scale, meaning offensive actors will have access to the same capability.

Redis Lua RCE (CVE-2024-46981, EPSS 76%)

CVE-2024-46981 affects Redis and involves Lua library commands leading to remote code execution. EPSS scores this at 76% (99th percentile), indicating high exploitation probability. The MSRC entry is published, meaning Microsoft has acknowledged relevance to its ecosystem (Azure Cache for Redis or Windows-hosted Redis instances).

Glibc ld.so Privilege Escalation (CVE-2023-4911, CISA KEV)

CVE-2023-4911 is a buffer overflow in glibc's ld.so (the "Looney Tunables" vulnerability) leading to local privilege escalation. CISA-KEV listed, EPSS 64% (98th percentile), with a prior remediation deadline of December 12, 2023. If any Linux systems in your environment are still running unpatched glibc, they are vulnerable to local privilege escalation by any authenticated user.

Azure IoT Platform Device SDK RCE (CVE-2024-21646, EPSS 85th percentile)

CVE-2024-21646 is a remote code execution vulnerability in the Azure IoT Platform Device SDK. EPSS scores this in the 85th percentile. Organizations using Azure IoT or embedding the SDK in connected devices should verify they are running a patched SDK version.

Python setuptools RCE via VCS URLs (CVE-2024-6345, EPSS 89th percentile)

CVE-2024-6345 is a remote code execution vulnerability in pypa/setuptools triggered when processing malicious VCS (version control system) URLs. EPSS scores this at the 89th percentile. Any Python-based build pipeline or developer workstation installing packages from untrusted sources is at risk.


General Security News

Trend: Legacy CVEs Still Actively Exploited

Two of today's CISA KEV additions are over a decade old: CVE-2008-0015 (Windows Video ActiveX, 2008) and CVE-2020-7796 (Zimbra SSRF, 2020). Both still have active exploitation confirmed. This is consistent with the broader pattern of threat actors targeting long-tail unpatched systems. SMBs running older Windows environments or legacy collaboration platforms (Zimbra) should treat these as live threats, not historical footnotes.

AI Vulnerability Research: Scale and Speed Are Changing the Threat Landscape

The AISLE system's discovery of 13 of 14 OpenSSL CVEs assigned in 2025 demonstrates that AI-assisted fuzzing and vulnerability discovery is moving from research novelty to operational capability. Three bugs had survived 25+ years of human and automated review. The implication is that the time between vulnerability discovery and public exploit availability will compress further. Patch windows are shrinking.


Trends & Context

Today's brief clusters around two themes: actively exploited legacy vulnerabilities that organizations have failed to remediate (CVE-2008-0015, CVE-2020-7796, CVE-2023-4911) and new critical infrastructure threats from nation-state actors targeting appliances that lack EDR coverage (Dell RecoverPoint, Ivanti). The China-nexus UNC6201 campaign against backup and recovery infrastructure is a direct threat to ransomware resilience. If attackers can backdoor your backup appliance, your recovery capability is compromised before the ransomware even deploys. Prioritize patching edge appliances and network-attached infrastructure tools alongside endpoint patching programs.