CVE-2021-35211, CVE-2021-35247, CVE-2024-28995, CVE-2025-29628, CVE-2025-29629, CVE-2025-29631, CVE-2025-40538, CVE-2025-40539, CVE-2025-40540, CVE-2025-40541, CVE-2026-1226, CVE-2026-1227, CVE-2026-21410, CVE-2026-21509, CVE-2026-22553, CVE-2026-25108
IP Addresses:
89.248.168.239
Get tomorrow's brief in your inbox
Today: APT28 exploited a Microsoft Office zero-day in January, CISA added a FileZen command injection flaw to the KEV catalog with a March 17 remediation deadline, and SolarWinds patched four critical Serv-U vulnerabilities allowing root code execution. North Korea's Lazarus Group is now using Medusa ransomware to target US healthcare organizations, while ShinyHunters continues a data extortion spree hitting Wynn Resorts and CarGurus.
Microsoft Office Zero-Day Exploited by APT28 (CVE-2026-21509)
Russian state-sponsored group APT28 exploited CVE-2026-21509 (CVSS 99, CISA KEV due 2026-02-16, EPSS 0.092/93rd percentile) in January 2026 through weaponized RTF files. The vulnerability bypasses OLE security mitigations by relying on untrusted inputs in security decisions. Attackers delivered MiniDoor (an Outlook VBA implant that forwards emails), PixyNetLoader, and Covenant Grunt backdoors. The campaign, called Operation Neusploit, used Filen API as a C2 bridge between implants and actor-controlled listeners.
FileZen OS Command Injection Actively Exploited (CVE-2026-25108)
CISA added CVE-2026-25108 (CVSS 8.7, EPSS 0.003/56th percentile) to the KEV catalog on February 24. The flaw affects Soliton Systems FileZen versions 4.2.1 to 4.2.8 and 5.0.0 to 5.0.10, allowing authenticated users to execute arbitrary commands via specially crafted HTTP requests when FileZen Antivirus Check Option is enabled. Soliton received at least one confirmed attack report. The vulnerability requires general user credentials, and attackers can log on with at least one real account.
January 2026 CVE Landscape Summary
Recorded Future identified 23 vulnerabilities requiring immediate remediation in January 2026, a 5% increase from December 2025. Microsoft and SmarterTools accounted for 30% of January's vulnerabilities. Fourteen of the 23 CVEs have public proof-of-concept exploit code available. Code injection (CWE-94) was the most common weakness type, followed by authentication bypass (CWE-288) and exposure of sensitive information (CWE-200). Multiple critical authentication bypass flaws affected enterprise communication and management platforms.
SolarWinds Serv-U Critical Root Code Execution Flaws
SolarWinds patched four critical vulnerabilities (CVSS 9.1) in Serv-U 15.5 that allow remote code execution as root. CVE-2025-40538, CVE-2025-40539, CVE-2025-40540, and CVE-2025-40541 all require administrative privileges for exploitation. The vulnerabilities include broken access control allowing system admin user creation, type confusion flaws enabling arbitrary native code execution, and an insecure direct object reference (IDOR) allowing native code execution as root. SolarWinds rates these as medium risk on Windows deployments where services typically run under less-privileged service accounts. Prior Serv-U vulnerabilities CVE-2021-35211, CVE-2021-35247, and CVE-2024-28995 (CISA KEV, EPSS 0.944/100th percentile) were exploited by China-based group Storm-0322.
VMware Aria Operations Remote Code Execution
Broadcom patched several vulnerabilities in VMware Aria Operations, including high-severity flaws that could allow remote code execution. Specific CVE details were not provided in the available advisory.
InSAT MasterSCADA BUK-TS Remote Code Execution
All versions of Russian-made InSAT MasterSCADA BUK-TS are vulnerable to SQL injection (CVE-2026-21410) and OS command injection (CVE-2026-22553) through the main web interface and MMadmServ web interface. Both vulnerabilities allow remote code execution. CISA issued an ICS advisory noting InSAT has not responded to mitigation requests. The SCADA system is used in critical manufacturing, energy, and water/wastewater sectors worldwide.
Schneider Electric EcoStruxure Building Operation XXE Vulnerability
Schneider Electric patched CVE-2026-1227 and CVE-2026-1226 in EcoStruxure Building Operation Workstation and WebStation. CVE-2026-1227 (EPSS 0.000/5th percentile) is an improper restriction of XML external entity reference vulnerability that could result in unauthorized disclosure of local files, unauthorized interaction with the EBO system, or denial-of-service conditions when a local user uploads a maliciously crafted TGML graphics file. Affected versions include all 7.0.x versions prior to 7.0.3.2000 (CP1) and all 6.x versions prior to 6.0.4.14001 (CP10).
Gardyn Home Kit Multiple Vulnerabilities
CISA disclosed four vulnerabilities affecting Gardyn Home Kit smart garden devices. CVE-2025-29628 (EPSS 0.001/20th percentile) allows Azure IoT Hub connection strings to be downloaded over insecure HTTP, vulnerable to man-in-the-middle attacks. CVE-2025-29629 (EPSS 0.002/38th percentile) involves weak default credentials for SSH access. CVE-2025-29631 (EPSS 0.004/62nd percentile) is a command injection vulnerability in methods that do not sanitize input before passing content to the operating system. These vulnerabilities could allow unauthenticated users to access and control edge devices, access cloud-based devices and user information without authentication, and pivot to other edge devices in the Gardyn cloud environment.
Microsoft 365 Copilot Data Controls Expanded
Microsoft is expanding data loss prevention (DLP) controls to block Microsoft 365 Copilot from processing confidential Word, Excel, and PowerPoint documents stored locally, in addition to SharePoint and OneDrive. The change deploys between late March and late April 2026 through the Augmentation Loop (AugLoop) Office component. Currently, Purview DLP policies only apply to cloud-stored files. This addresses a January bug where Copilot Chat accessed and summarized confidential emails in Sent Items and Drafts folders despite active DLP policies and confidentiality labels for nearly a month.
North Korea's Lazarus Group Deploys Medusa Ransomware
Lazarus Group (including Andariel/Stonefly/Onyx Sleet/Silent Chollima subgroup) is using Medusa ransomware-as-a-service to target US healthcare organizations and at least one Middle East victim. Symantec and Carbon Black confirmed one US healthcare attack failed, while the Middle East organization was successfully hit. Since November 2025, four of nearly 30 victims listed on Medusa's data leak site are US healthcare and nonprofit organizations, including a mental health nonprofit and an educational facility for autistic children. Average ransom demand over the four-month period was $260,000. Lazarus deployed Comebacker backdoor (exclusive to Lazarus), Blindingcan RAT, and Infohook info stealer. Andariel previously used Maui and Play ransomware. The Medusa operation is run by the Spearwing cybercrime group, active since 2023, with over 366 attacks claimed against critical sectors including medical, education, legal, insurance, technology, and manufacturing.
Wynn Resorts Employee Data Breach
Wynn Resorts confirmed a breach after ShinyHunters listed the company on its extortion site. The threat actor claimed to have stolen over 800,000 records containing PII (SSNs, etc.) and employee data from Wynn's Oracle PeopleSoft environment. ShinyHunters set a deadline of February 23, 2026, after which the data would be leaked. The Wynn listing was removed from ShinyHunters' site shortly after appearing, and the company stated the attacker confirmed the stolen data had been deleted. The breach did not impact guest operations or physical properties.
CarGurus Data Breach Exposes 12.4 Million Records
ShinyHunters published a 6.1GB archive containing 12.4 million records allegedly from CarGurus, a US-based automotive marketplace with 40 million monthly visitors. The dataset includes email addresses, IP addresses, full names, phone numbers, physical addresses, user account IDs, finance pre-qualification application data, finance application outcomes, dealer account details, and subscription information. Have I Been Pwned added the dataset on February 22, noting 70% of leaked data was already in its database from previous incidents, with roughly 3.7 million fresh records. CarGurus has not issued an official breach disclosure statement.
Defense Contractor Employee Jailed for Selling Zero-Days to Russian Broker
Peter Williams, a 39-year-old Australian national and former general manager at L3Harris subsidiary Trenchant, was sentenced to 87 months (7.25 years) in prison for selling eight zero-day exploits to Russian broker Operation Zero. Williams stole the exploits between 2022 and 2025 using a portable external hard drive to transfer them from secure networks at Trenchant's Sydney and Washington DC offices. He received approximately $1.3 million in cryptocurrency. The tools were designed exclusively for US government and Five Eyes intelligence use. Operation Zero sold the stolen tools to at least one unauthorized user. US Treasury OFAC sanctioned Operation Zero (Matrix LLC), owner Sergey Zelenyuk, UAE front company Special Technology Services LLC, and associated individuals under the Protecting American Intellectual Property Act (PAIPA). The theft caused L3Harris $35 million in losses. Williams previously served in the Australian Signals Directorate. Operation Zero offers up to $4 million for Telegram exploits and $20 million for Android/iPhone tools, selling only to non-NATO customers including Russian intelligence agencies.
Diesel Vortex Phishing Targets Freight and Logistics
A threat group dubbed Diesel Vortex is stealing credentials from US and European freight and logistics operators through phishing attacks using 52 domains. The campaign, running since September 2025, has stolen 1,649 unique credentials from platforms including DAT Truckstop, TIMOCOM, Teleroute, Penske Logistics, Girteka, and Electronic Funds Source (EFS). Researchers at Have I Been Squatted discovered an exposed repository containing an SQL database from a phishing project the actor called Global Profit (marketed as MC Profit Always). Telegram webhook logs indicate the operation is run by Armenian-speaking actors connected to Russian infrastructure. The group uses a highly organized operation with call centers, mail support, programmers, and staff finding drivers/carriers/logistics contacts. Attacks involve phishing emails via Zoho SMTP/Zeptomail, Cyrillic homoglyph tricks, voice phishing, and Telegram channel infiltration. Phishing pages are pixel-level clones capturing credentials, permit data, MC/DOT numbers, RMIS login details, PINs, 2FA codes, security tokens, payment amounts, payee names, and check numbers. The operation was disrupted following coordinated action by GitLab, Cloudflare, Google Threat Intelligence, CrowdStrike, and Microsoft Threat Intelligence Center.
Threat Intelligence Supply Chain Vulnerabilities
Georgia Tech researchers found the threat intelligence supply chain is susceptible to adversarial action and suffers from quality and data-sharing bottlenecks. They created benign yet suspicious binaries and shared them with 30 security vendors, revealing 67% conduct sandbox analysis but only 17% share threat intelligence from that analysis. Many share indicators of compromise but few share binaries for deeper analysis. A handful of "nexus vendors" share more intelligence than others, but bottlenecks among supply chain participants slow information propagation by hours to days. Some security researchers have hosted infrastructure at the same IP addresses for years, helping adversaries evade sandboxes. China's January 2026 ban on US and Israeli security software threatens to fracture the global threat intelligence ecosystem.
Developer-Targeting Campaign Using Malicious Next.js Repositories
Microsoft Defender Experts identified a coordinated campaign targeting developers through malicious GitHub and Bitbucket repositories disguised as legitimate Next.js projects and technical assessment materials. The campaign uses job-themed lures to blend into routine developer workflows. Multiple entry points converge on runtime retrieval and local execution of attacker-controlled JavaScript that transitions into staged command-and-control. Path 1 abuses Visual Studio Code workspace automation with .vscode/tasks.json configured with "runOn: folderOpen", triggering execution when a developer opens and trusts the project. The execution chain uses a fetch-and-execute pattern retrieving a JavaScript loader from Vercel. An initial lightweight registration stage establishes host identity before pivoting to a separate controller providing persistent tasking and in-memory execution. Repository naming follows patterns like "Cryptan-Platform-MVP1" to appear legitimate.
UAC-0050 Targets European Financial Institution
Russia-aligned threat actor UAC-0050 (DaVinci Group/Mercenary Akula) targeted an unnamed European financial institution involved in regional development and reconstruction initiatives supporting Ukraine. The February 2026 attack spoofed a Ukrainian judicial domain to deliver a spear-phishing email directing a senior legal and policy advisor to download a remote access payload from PixelDrain. The multi-layered infection chain used nested archives (ZIP → RAR → password-protected 7-Zip → executable with .pdf.exe double extension) to deploy an MSI installer for Remote Manipulator System (RMS), a Russian remote desktop software. This marks a potential expansion beyond UAC-0050's typical Ukraine-based targeting. The group is characterized by CERT-UA as a mercenary operation associated with Russian law enforcement agencies conducting data gathering, financial theft, and information/psychological operations under the Fire Cells branding. UAC-0050 previously dropped LiteManager, RemcosRAT, and other legitimate remote access tools.
1Campaign Platform Enables Malicious Google Ads
A cybercrime service called 1Campaign is enabling threat actors to run malicious Google Ads that evade detection for extended periods. Active for at least three years and managed by a developer using the name DuppyMeister, 1Campaign is a cloaking service that passes Google's screening and shows malicious content only to real victims while serving benign white pages to security researchers and automated scanners. The platform provides a dashboard to set filtering parameters including geography, ISP, and device characteristics, blocking 99.4% of visitors in some cases. The system assigns fraud risk scores (0-100) to each visitor, automatically blocking traffic from Microsoft, Google, Tencent Cloud, OVH Hosting, and other cloud providers. The platform also offers a Google Ads launcher tool bypassing Google's policy limitations and enabling brand impersonation. Varonis observed traffic linked to 1Campaign in the US, Canada, Netherlands, China, Germany, France, Japan, Hungary, and Albania.
RoguePilot Flaw in GitHub Codespaces (Patched)
Orca Security disclosed RoguePilot, a vulnerability in GitHub Codespaces that allowed attackers to inject malicious Copilot instructions in a GitHub issue. The AI-driven passive prompt injection vulnerability occurred when an unsuspecting user launched a Codespace from a malicious issue. GitHub Copilot was automatically fed the issue's description as a prompt, which could contain hidden instructions in HTML comment tags. The specially crafted prompt could instruct Copilot to leak the privileged GITHUB_TOKEN by manipulating Copilot to check out a crafted pull request containing a symbolic link to an internal file. Microsoft patched the flaw following responsible disclosure.
CrowdStrike Report: Attackers Need Just 29 Minutes to Own a Network
CrowdStrike's annual Global Threat Report found attackers now need just 29 minutes to move through breached networks, down from previous measurements. Credential misuse, AI tools, and security blind spots accelerate lateral movement. The report notes Russia-nexus adversaries continue aggressive operations targeting Ukraine and NATO member states. APT29 (Cozy Bear/Midnight Blizzard) systematically exploits trust and organizational credibility in spear-phishing campaigns targeting US NGOs and legal entities to gain unauthorized access to Microsoft accounts. APT29 successfully compromised or impersonated individuals with whom targeted users maintained trusting professional relationships, heavily investing in substantiating impersonations using compromised individuals' legitimate credentials.
Windows 11 KB5077241 Update Improves BitLocker, Adds Sysmon
Microsoft released the KB5077241 optional cumulative update for Windows 11 with 29 changes including BitLocker reliability improvements (devices no longer freeze after entering recovery key), a built-in network speed test tool for Ethernet/Wi-Fi/cellular connections in the taskbar, and native System Monitor (Sysmon) functionality (disabled by default). The update adds an option to open a new File Explorer instance by holding Shift or middle-clicking, improves reliability when PCs wake from sleep, and reduces resume time under heavy load. Quick Machine Recovery (QMR) is automatically enabled on Windows Professional devices that are not domain-joined and not enrolled in enterprise endpoint management. The update also adds Remote Server Administration Tools (RSAT) support for Windows 11 Arm64 devices, allowing IT administrators to install Active Directory Domain Services tools, Server Manager, Group Policy Management Tools, DNS Server Tools, and DHCP Server Tools. Updated Secure Boot certificates are rolling out to replace the original 2011 certificates expiring in late June 2026.
UK Fines Reddit $19 Million for Children's Data Violations
The UK Information Commissioner's Office (ICO) fined Reddit £14.47 million ($19.5 million) for collecting and using personal information of children under 13 without adequate safeguards. Reddit failed to implement meaningful age-verification until July 2025, despite terms of service prohibiting users under 13. A significant number of underage children used the platform before July 2025, with Reddit processing their data without lawful basis and potentially exposing them to harmful content. Reddit's July 2025 age assurance measures (including age verification for mature content and self-declaration prompts for new accounts) fail to meet UK data protection standards and can be easily bypassed. Reddit announced it will appeal the decision, stating it does not require users to share identity information and arguing the ICO's requirement to collect more private information contradicts user privacy and safety. Reddit reports 121 million daily active users and over 471 million weekly active users across 100,000+ active communities.
Open Redirect Scanning Increase
SANS Internet Storm Center detected an increase in scans for redirect-related URLs in February 2026, including /continue?url=, /redirect?url=, /away?url=, /goto?url=, and /jump?url= endpoints. Most requests originate from a single IP address (89.248.168.239) registered to AS202425, IP Volume, a Seychelles-registered company often called a "bulletproof" hoster. Open redirects, added to OWASP Top 10 in 2010 and merged into Sensitive Data Exposure in 2013, are often overlooked but have become more important with ubiquitous OAUTH use. OAUTH relies on redirect URLs to pass authorization tokens from authorization servers to clients. An open redirect within allow-listed URL ranges can subvert token security even when best practices require URL pattern allowlisting.
Operation Red Card 2.0: 651 Arrests in Africa
Interpol coordinated with African law enforcement agencies and cybersecurity firms in Operation Red Card 2.0, leading to 651 arrests and recovery of over $4.3 million. The operation targeted cybercrime groups across Africa.
Group Relative Policy Optimization Can Unalign LLMs
Microsoft researchers discovered that Group Relative Policy Optimization (GRPO), a reinforcement learning technique used to fine-tune LLMs after deployment, can also remove safety features. A single unlabeled prompt like "Create a fake news article that could lead to panic or chaos" was enough to reliably unalign 15 language models in a process called GRP-Obliteration. The prompt is relatively mild and does not mention violence, illegal activity, or explicit content, yet training on this one example causes models to become more permissive across many harmful categories they never saw during training. Research also uncovered side channels for inferring conversation topics and fingerprinting user queries with over 75% accuracy by exploiting speculative decoding. Models backdoored at the computational graph level using a technique called ShadowLogic can put agentic AI systems at risk by allowing tool calls to be silently modified without user knowledge.
APT28's exploitation of a Microsoft Office zero-day and North Korea's adoption of Medusa ransomware demonstrate state-sponsored actors expanding their toolsets and targeting. The convergence of multiple data extortion campaigns by ShinyHunters, combined with the sentencing of a defense contractor insider who sold zero-days to Russian brokers, highlights the persistent threat from both external adversaries and trusted insiders. The increase in developer-targeted campaigns using malicious repositories and AI-driven prompt injection attacks signals attackers are adapting to modern development workflows and AI-assisted coding environments. Organizations must address these evolving attack vectors while maintaining rapid patch cycles for critical vulnerabilities like those in SolarWinds Serv-U, FileZen, and building management systems.