← Carolina Clear Tech

Cyber Threat Brief

2026-02-23

Listen to this brief (15:43)

Download MP3
Show Notes

Show Notes - 2026-02-23

Stories Covered

CVEs Referenced

CVE-2023-27532, CVE-2024-40711, CVE-2026-1281, CVE-2026-1340, CVE-2026-22769, CVE-2026-2329

Indicators of Compromise

IP Addresses: 6.0.3.1, 1.0.7.81

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Cyber Threat Brief - February 23, 2026

Today: Dell RecoverPoint zero-day exploited since mid-2024 gets CVSS 10.0 and active Chinese APT targeting. Ivanti EPMM zero-days under widespread attack with patches available. France loses 1.2 million bank records to credential theft. Mississippi hospital system closes all clinics after ransomware hit.

Critical Alerts

Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769)

Dell RecoverPoint for Virtual Machines versions before 6.0.3.1 contain CVE-2026-22769, a CVSS 10.0 critical vulnerability exploited as a zero-day since mid-2024 by Chinese threat group UNC6201. The flaw involves hardcoded Tomcat credentials enabling unauthenticated root access. Attackers deployed SLAYSTYLE, BRICKSTORM, and GRIMBOLT backdoors, then created Ghost NICs for lateral movement and persistence in VMware environments. CISA added this to the KEV catalog with a February 21 remediation deadline (already passed). EPSS score is 0.288 (96th percentile).

Ivanti EPMM Zero-Days Under Active Exploitation (CVE-2026-1281, CVE-2026-1340)

Ivanti Endpoint Manager for Mobile contains two actively exploited zero-days, both rated CVSS 9.8. Unit 42 reports widespread attacks targeting US, German, Australian, and Canadian organizations across government, healthcare, manufacturing, professional services, and tech sectors. Attackers establish reverse shells, install web shells, download malware, and conduct reconnaissance for further vulnerabilities. Patches are available and require no downtime. CVE-2026-1281 has EPSS 0.543 (98th percentile) and CVE-2026-1340 has EPSS 0.387 (97th percentile). Both are on CISA KEV with a February 1 due date (missed by most organizations).

Veeam Exploited in Russian Credential Abuse Campaign (CVE-2023-27532, CVE-2024-40711)

Russian-speaking financially motivated threat actors leveraged commercial generative AI tools to conduct mass credential abuse against 600 FortiGate devices across 55 countries between January 11 and February 18, 2026. Attackers targeted Veeam Backup and Replication servers, exploiting CVE-2023-27532 and CVE-2024-40711. Both vulnerabilities are linked to ransomware operations and appear on CISA KEV. CVE-2023-27532 has EPSS 0.827 (99th percentile) with a September 2023 due date. CVE-2024-40711 has EPSS 0.682 (99th percentile) with November 2024 due date. Check Point IPS provides protection.

AI Assistants Abused as C2 Proxies

Check Point Research demonstrated a technique that repurposes AI assistants like Grok and Microsoft Copilot as covert command-and-control proxies. Attackers abuse web-browsing URL fetch features without authentication. Malware exfiltrates host data via query parameters and retrieves commands from AI-generated summaries through hidden WebView2 components. This bypasses traditional inspection of AI traffic.

Vulnerability Disclosures

Grandstream GXP1600 VoIP Phone RCE (CVE-2026-2329)

Grandstream GXP1600 series VoIP phones contain CVE-2026-2329, a critical unauthenticated stack-based buffer overflow in the web API allowing root remote code execution. Exploitation enables credential theft, SIP proxy reconfiguration, and covert call interception. Firmware version 1.0.7.81 patches the issue. EPSS score is low at 0.001 (34th percentile). Check Point IPS provides protection.

Microsoft 365 Copilot DLP Bypass

A flaw in Microsoft 365 Copilot allows the Work Tab Chat feature to summarize emails protected by confidentiality sensitivity labels, bypassing configured Data Loss Prevention policies. The code-level defect circumvents DLP controls designed to protect sensitive information.

RoundCube Webmail XSS Vulnerability Exploited

A RoundCube Webmail vulnerability patched in December 2025 is now under active exploitation. The flaw enables XSS attacks via animate tags in SVG documents.

Ransomware & Extortion

University of Mississippi Medical Center Ransomware Attack

University of Mississippi Medical Center suffered a ransomware attack forcing closure of all 36 clinics statewide and cancellation of elective procedures. Unauthorized access occurred February 15. The attack disrupted electronic medical records, forcing manual processes. No ransomware group has claimed responsibility. The potential compromise of patient and employee data remains unclear.

Advantest Corporation Ransomware Incident

Japanese tech giant Advantest Corporation experienced a ransomware attack following unauthorized network access on February 15. The incident impacted internal systems. The extent of customer or employee data compromise is unclear.

0APT Ransomware-as-a-Service Operation

Cyderes Howler Cell warns that 0APT, previously suspected as a fake ransomware gang, operates an active Ransomware-as-a-Service platform with functional malicious payloads and a working affiliate model. Researchers accessed the group's RaaS portal and collected viable malware samples ready for deployment. The 0APT ransomware demonstrates focus on reliability, operator configurability, and secure cryptographic implementation using Rust-based development. The group may be attempting to attract affiliates through quick reputation gains.

Business & Infrastructure Threats

France National Bank Account Registry Breach

An attacker accessed FICOBA, France's national bank account registry, using compromised government credentials in January 2026. The breach exposed data tied to 1.2 million accounts including names, addresses, account identifiers, and tax identification numbers. Access was restricted immediately upon discovery, but the attacker successfully exfiltrated the data before containment.

Ukraine National Bank Supply-Chain Incident

Ukraine's National Bank faced a supply-chain incident affecting a contractor running its collectible coin online store. Exposed information includes customer registration data such as names, emails, phone numbers, and delivery addresses. Payment information was not affected.

npm Supply-Chain Worm Targets AI Coding Assistants

Researchers discovered a Shai-Hulud-like npm supply-chain worm spreading via typosquatted packages. The worm steals developer and CI secrets, exfiltrates via GitHub API with DNS fallback, and propagates by poisoning workflows and git hooks. The malware includes MCP server injection targeting AI coding assistants and harvests LLM API keys.

PayPal Data Breach Leads to Fraudulent Transactions

PayPal disclosed a data breach caused by an application error that exposed customer personal information for nearly six months. The exposure led to fraudulent transactions.

AI Quadruples Data Exfiltration Speed

Unit 42's 2026 Global Incident Response Report reveals AI contributed to a quadrupling of exfiltration speeds in 2025, acting as a force multiplier increasing attacker success rates at each campaign stage. AI is rapidly becoming one of the most dangerous emerging threats for 2026.

General Security News

Arkanix Stealer: AI-Assisted Malware Experiment

Kaspersky analyzed Arkanix Stealer, an information-stealing malware operation promoted on dark web forums in late 2025. The project was likely AI-assisted, with evidence of LLM-assisted development drastically reducing development time and costs. The malware offered Python and premium C++ versions with data-stealing capabilities targeting browsers, cryptocurrency wallets, VPN credentials, and gaming platforms. The premium version included ChromElevator post-exploitation tool bypassing Google's App-Bound Encryption. The author shut down operations without notice after two months. Kaspersky assesses Arkanix as more of a public software product experiment than a traditional stealer operation.

MuddyWater Targets MENA with New Malware

Iranian threat group MuddyWater (aka Earth Vetala, Mango Sandstorm, MUDDYCOAST) targeted organizations and individuals across the Middle East and North Africa in Operation Olalampo. Activity began January 26, 2026, deploying new malware families including GhostFetch, CHAR, and HTTP_VIP.

Trends & Context

Zero-day exploitation dominates this briefing with three critical vulnerabilities under active attack. Dell RecoverPoint's CVSS 10.0 rating combined with Chinese APT activity and the Ivanti EPMM widespread exploitation represent immediate threats to enterprise infrastructure. The credential-based attacks against France's banking registry and FortiGate devices highlight the continued effectiveness of stolen credentials as an attack vector. AI's dual role as both attack tool (C2 proxies, credential abuse acceleration) and development accelerator (Arkanix Stealer) signals a fundamental shift in the threat landscape that defenders must adapt to rapidly.