CVE-2024-12356, CVE-2025-49113, CVE-2025-68461, CVE-2026-1731, CVE-2026-20761, CVE-2026-22769, CVE-2026-22885, CVE-2026-24455, CVE-2026-25715, CVE-2026-26048, CVE-2026-26049, CVE-2026-26119
Domains:
178[.]128, 69[.]245, trustconnectsoftware[.]com
Get tomorrow's brief in your inbox
Today: Chinese state-linked threat cluster UNC6201 has exploited a maximum-severity hardcoded credential flaw in Dell RecoverPoint (CVE-2026-22769) since mid-2024, deploying novel backdoors across federal and enterprise networks, and CISA's patch deadline hits tomorrow, February 21. BeyondTrust's critical pre-auth RCE (CVE-2026-1731, CVSS 9.9) has been adopted by ransomware operators with over 16,400 vulnerable instances still reachable online. A ransomware attack on the University of Mississippi Medical Center shut down all clinics statewide and cut Epic EMR access for thousands of patients.
CISA 3-Day Deadline: Dell RecoverPoint Hardcoded Credential Flaw (CVE-2026-22769)
CISA added CVE-2026-22769 to the KEV catalog on February 19 with a federal remediation deadline of February 21 - tomorrow. The flaw is a maximum-severity hardcoded credential vulnerability in Dell RecoverPoint for Virtual Machines, a VMware backup and recovery solution. Mandiant and Google's Threat Intelligence Group confirmed that UNC6201, a suspected China-nexus threat cluster with hallmarks overlapping Silk Typhoon (also tracked as UNC5221), has exploited this flaw since at least mid-2024 to move laterally, maintain persistence, and deploy malware including SLAYSTYLE, BRICKSTORM, and a newly identified backdoor called GRIMBOLT. Attackers also created "Ghost NICs" on virtual machines to pivot across compromised environments without triggering network alerts. EPSS sits at the 96th percentile; fewer than a dozen confirmed victims are known, though actual count is likely higher given the group's tradecraft. Silk Typhoon previously breached U.S. Treasury, OFAC, and CFIUS.
BeyondTrust CVE-2026-1731 Now Confirmed in Ransomware Campaigns (CVSS 9.9)
CVE-2026-1731 is a pre-authentication OS command injection vulnerability in BeyondTrust Remote Support (25.3.1 and earlier) and Privileged Remote Access (24.3.4 and earlier), exploitable via a malformed WebSocket connection targeting the thin-scc-wrapper component. CISA's KEV entry has been updated to confirm ransomware campaign use; the original federal remediation deadline was February 16. Unit 42 identified over 16,400 exposed vulnerable instances and documented full attack chains including web shell deployment, VShell and SparkRAT installation, lateral movement, and complete PostgreSQL database exfiltration targeting financial services, legal, healthcare, and technology sectors across the US, France, Germany, Australia, and Canada. EPSS is at the 98th percentile. The same BeyondTrust codebase was previously exploited via CVE-2024-12356 by Silk Typhoon, reflecting a pattern of recurring input validation failures in distinct execution pathways within the product.
RoundCube Webmail: Two Actively Exploited Flaws Added to CISA KEV
CISA added CVE-2025-49113 (deserialization of untrusted data, EPSS 100th percentile) and CVE-2025-68461 (cross-site scripting) to the KEV catalog, both with a remediation deadline of March 13, 2026. RoundCube has been a persistent target for nation-state actors including APT28; deserialization flaws in web mail platforms are a reliable path to server-side code execution and credential harvesting.
Windows Admin Center Privilege Escalation - Potential Domain Compromise (CVE-2026-26119, CVSS 8.8)
Microsoft patched an improper authentication vulnerability in Windows Admin Center version 2511 (released December 2025). CVE-2026-26119 allows an authenticated network attacker to escalate privileges to the level of the user running the application. Semperis researcher Andrea Pierini, who discovered the flaw, stated it can enable full domain compromise from a standard user account under certain conditions. Microsoft tagged it "Exploitation More Likely." No in-the-wild exploitation is confirmed yet, but technical details are expected to become public soon.
Ivanti Exploitation Surges - Zero-Days Traced to July 2025
Researchers have identified a surge in exploitation of Ivanti products, with zero-day attacks now traced back to July 2025, months before public disclosure. Observed activity includes web shell deployment, reconnaissance tooling, and malware downloads. The pattern continues multi-year targeting of Ivanti appliances by nation-state actors.
PUSR USR-W610 Industrial Router: Four Vulns, EOL, No Patch Coming
CISA issued an advisory for the Jinan USR IOT USR-W610 router covering four vulnerabilities: CVE-2026-25715 (blank password disables all authentication across web interface and Telnet), CVE-2026-24455 (HTTP Basic Auth transmitted in cleartext, credentials passively interceptable), CVE-2026-26049 (passwords rendered in plaintext in the UI), and CVE-2026-26048 (Wi-Fi deauthentication via forged management frames, no MFP). The vendor confirmed the device is end-of-life with no patches planned. The device is deployed worldwide in critical manufacturing environments.
EnOcean SmartServer IoT: Remote Code Execution via Crafted Messages (CVE-2026-20761)
CVE-2026-20761 allows unauthenticated remote attackers to execute arbitrary OS commands via crafted LON IP-852 messages on SmartServer IoT devices running version 4.60.009 or earlier. CVE-2026-22885 is a companion out-of-bounds read in the same pathway causing memory disclosure. A patched version is available.
UMMC Ransomware: All Mississippi Clinics Closed, Epic EMR Offline
The University of Mississippi Medical Center confirmed a ransomware attack on February 20 that shut down all outpatient clinics statewide, cancelled ambulatory surgeries and imaging appointments, and took Epic electronic medical records offline. UMMC operates seven hospitals, 35 clinics, and over 200 telehealth sites and is Mississippi's only Level I trauma center and only children's hospital. Hospital officials confirmed active communications with the ransomware operators. The FBI and CISA are assisting with investigation. No group has claimed the attack; data theft has not been confirmed but is likely given the negotiation posture. In-patient care is continuing via paper downtime procedures.
Advantest Ransomware Attack - $120B Semiconductor Test Equipment Maker
Japanese semiconductor test equipment maker Advantest (7,600 employees, $5B annual revenue, $120B market cap) disclosed a ransomware attack detected February 15 affecting portions of its corporate network. Affected systems have been isolated, third-party incident responders are engaged, and investigation into potential customer or employee data exposure is ongoing. No group has claimed the attack. Advantest joins a string of recent high-profile Japanese corporate incidents including Washington Hotel, Nissan, Muji, and NTT.
LockBit 5.0 Cross-Platform Build Explicitly Targets Proxmox
Analysis of LockBit 5.0 reveals Windows builds with layered defense evasion: DLL unhooking, process hollowing, ETW function patching, and log clearing. The variant includes a dedicated Proxmox build, explicitly targeting the open-source hypervisor that enterprises are adopting as a VMware alternative. Organizations migrating from VMware to Proxmox should account for this in their ransomware resilience planning.
ClickFix + Matanbuchus 3.0 + AstarionRAT: Domain Controllers Compromised in Minutes
Huntress documented a February 2026 ClickFix campaign delivering Matanbuchus 3.0 that rapidly progressed from initial access to domain controller compromise via PsExec, rogue account creation, and Microsoft Defender exclusion staging in a single session. The campaign deployed AstarionRAT, a custom implant with 24 capabilities including credential theft, SOCKS5 proxy, port scanning, reflective code loading, and shell execution. ClickFix social engineering drove 53% of all malware loader activity in 2025.
TrustConnect: Fully Fake RMM Vendor Selling a RAT for $300/Month
Proofpoint uncovered an operation that built a complete fake remote management software company, TrustConnect, with an AI-generated business website, Extended Validation code-signing certificate, and a cryptocurrency subscription model at $300/month. The product is a remote access trojan with full mouse/keyboard control, screen recording, file transfer, and UAC bypass. The EV certificate has been revoked and the primary C2 (178[.]128[.]69[.]245) was disrupted February 17, but operators pivoted to new infrastructure within hours and are testing a rebranded variant called "DocConnect" or "SHIELD OS v1.0." Attribution links this to a Redline infostealer operator via a Telegram handle identified in Operation Magnus. RMM abuse jumped 277% in 2025 and now represents 24% of all observed incidents per Huntress data.
Cline CLI 2.3.0 Supply Chain Attack - OpenClaw Installed on ~4,000 Developer Systems
On February 17, an attacker used a compromised npm publish token to release Cline CLI 2.3.0 with a postinstall script silently installing openclaw@latest on developer machines. Approximately 4,000 installs occurred during the eight-hour exposure window. The token was compromised via "Clinejection," a prompt injection attack against Cline's automated GitHub issue triage workflow where excessive Claude permissions allowed arbitrary code execution and npm token exfiltration. OpenClaw itself is not malicious, but the unauthorized installation demonstrates a complete supply chain integrity failure. Version 2.4.0 is the safe release; npm publishing has been migrated to OIDC via GitHub Actions.
Identity Posture Gaps: What Cyber Insurers and Threat Actors Both Audit
With a third of cyberattacks involving compromised employee credentials, cyber insurers are embedding Active Directory hygiene directly into underwriting models. The specific factors under scrutiny align precisely with known attacker exploitation paths: password reuse across admin and service accounts, legacy NTLM still active in the environment, dormant accounts with valid credentials, service accounts with non-expiring passwords, and excessive Domain Admin membership. Insurers view uncontrolled privileged access as a predictor of rapid breach escalation; attackers use these paths for exactly the same reason.
Microsoft Guidance: Self-Hosted AI Agents Require Full Isolation
Microsoft Security published technical guidance on securing self-hosted AI agent runtimes, using OpenClaw as the reference architecture. Core risk: agent runtimes inherit the full privilege of the host environment, execute third-party code (skills), and process untrusted external inputs in a continuous loop. A single malicious input on an agent's feed can result in persistent credentialed execution and memory poisoning across the environment. Microsoft's minimum safe posture: isolated dedicated VM or physical system, non-privileged dedicated credentials, access to non-sensitive data only, continuous monitoring, and a documented rebuild plan. Organizations piloting autonomous AI agents on standard workstations connected to corporate AD are creating a high-value attack surface.
Remote access and backup infrastructure are the current preferred entry point for nation-state actors: Dell RecoverPoint and BeyondTrust Remote Support are both being exploited by China-linked threat clusters for persistent lateral access, and BeyondTrust's codebase has now yielded two significant vulnerabilities in rapid succession from the same root cause of insufficient input validation. Healthcare continues to absorb the most operationally damaging ransomware attacks, with UMMC's statewide clinic shutdown illustrating that the sector has minimal fallback when EMR systems go offline. The line between legitimate and malicious tooling is collapsing at the same time: threat actors are building fully fake RMM vendors with EV certificates, supply chain attacks are silently installing AI runtimes on developer machines, and ClickFix-driven loader campaigns are achieving domain compromise within a single attacker session.