Get tomorrow's brief in your inbox
Today: Telus Digital admits to breach with up to a petabyte stolen by ShinyHunters. Former ransomware negotiator indicted for feeding intel to BlackCat during active incidents. AI-powered attacks are scaling faster than defenders can respond, with exploits moving at machine speed against 15-day patch windows.
Citrix CISO Issues Emergency Patch Warning
Cloud Software Group (Citrix/Tibco) sent customers an urgent security advisory citing "evolving geopolitical landscape" and increased state-sponsored threats. CISO Kumar Palaniappan warned of marked uptick in attacks targeting critical infrastructure and supply chains, including APTs, ransomware campaigns, and zero-day exploitation attempts.
Ransomware Negotiator Indicted for Aiding BlackCat Gang
DOJ charged incident responder Angelo Martino with conducting cyberattacks and feeding information to ALPHV/BlackCat ransomware operators during active negotiations. Martino worked for DigitalMint as a ransomware negotiator while allegedly helping threat actors increase ransom demands. Two co-conspirators from Sygnia and DigitalMint (Ryan Goldberg and Kevin Martin) pleaded guilty in December to conspiracy to obstruct commerce by extortion. The group earned $1.2 million from an attack on a Florida medical company but failed to extort nine other victims. Both face up to 20 years in prison with sentencing on April 30.
Telus Digital Breach Leaks Up to One Petabyte
Canadian outsourcer Telus Digital confirmed a cyberattack involving "unauthorized access to a limited number of our systems." ShinyHunters crime gang claimed responsibility and reports indicate they stole a petabyte or more of data after acquiring valid Google Cloud Platform credentials from the Salesloft breach. Telus provides outsourcing services for major enterprises, amplifying the potential impact beyond the company itself.
Starbucks HR Portal Phishing Compromises 889 Employees
Starbucks disclosed that attackers spoofed the company's Partner Central HR portal and captured employee credentials through phishing. The breach exposed names, Social Security numbers, dates of birth, financial account numbers, and routing numbers for 889 staff members. Starbucks discovered the breach on February 6 and determined the unauthorized third party accessed employee accounts after victims used the fake portal.
AI Exploits Moving Faster Than Defenses Can Respond
Booz Allen Hamilton report warns that attackers are adopting AI more quickly than defenders, creating asymmetric advantage. Threat actors use LLMs to identify obscure perimeter vulnerabilities and establish persistence at machine speed. Example cited: HexStrike AI framework exploited thousands of Citrix Netscaler products in under 10 minutes using a single critical CVE. CISA's standard 15-day patch window is insufficient against AI-powered exploitation that operates in minutes.
Poland Nuclear Research Center Targeted
Poland's nuclear research center reported a hacking attempt. Initial evidence suggests Iran may be behind the attack, but officials acknowledge it could be a false flag operation. No additional details on the scope, success, or impact of the intrusion were provided.
Swedish E-Government Code Leaked
Threat actor ByteToBreach leaked source code from Sweden's e-government portal after breaching Swedish IT contractor CGI Group. The hacker claims to have stolen data on millions of Swedish citizens along with electronic signing documents. CGI Group confirmed the breach last Thursday.
Betterleaks Replaces Gitleaks for Secrets Scanning
Zach Rice, original author of Gitleaks, released Betterleaks as the successor after losing full control over the Gitleaks project. Betterleaks improves on Gitleaks with rule-defined validation using Common Expression Language, token efficiency scanning achieving 98.6% recall versus 70.4% for entropy-based scanning, pure Go implementation, automatic handling of encoded secrets, and parallelized Git scanning. The project uses the MIT open-source license and is maintained by contributors from Royal Bank of Canada, Red Hat, and Amazon.
Meta Takes Down Mexican Cartel Accounts
Meta suspended thousands of Facebook and Instagram accounts tied to Mexican and Latin American drug cartels in 2025. The accounts were used to recruit youth for trafficking, advertise drugs, and organize violence and extortion. Meta used AI to detect coded cartel language and identify drug photos, with human reviewers confirming findings before removal. Special warnings were shown to youth in Mexico, Brazil, Colombia, and Haiti when they interacted with cartel accounts, leading to increased account deactivation and unfriending. Some accounts were linked to fentanyl, cocaine, and meth trafficking into the US, as well as ATM fraud.
Former German Intelligence Official Falls for Signal Phishing
Arndt Freytag von Loringhoven, former high-ranking official in Germany's BND intelligence service and NATO, fell victim to a Signal phishing attack demanding his PIN code. Multiple high-ranking German politicians and intelligence officials were targeted in the campaign. Dutch intelligence agencies attributed the global Signal and WhatsApp account compromise campaign to Russian state-sponsored hackers.
Android 17 Blocks Non-Accessibility Apps from API
Android 17 Beta 2 introduces a new Advanced Protection Mode feature that prevents apps not classified as accessibility tools from using the accessibility services API. The API has been extensively abused by malware to steal sensitive data from compromised devices. When Advanced Protection Mode is enabled, only verified accessibility tools (screen readers, switch-based input, voice input, Braille access) with the isAccessibilityTool="true" flag can use the API. Password managers, antivirus software, automation tools, and launchers are excluded. Apps that already have permission will be automatically revoked when AAPM is active.
Trump Executive Order Labels Cybercrime as Transnational Organized Crime
The Trump administration released an executive order targeting cybercrime using language that designates cyber-enabled fraud as a product of transnational organized crime (TCOs). This jurisdictional framing authorizes federal law enforcement, diplomacy, and potential offensive cyber operations. The order calls for deploying the "full suite of U.S. government defensive and offensive cyber operations" and uses military doctrine language like "shaping" adversary behavior. The document does not rule out offensive action and follows proportionality doctrine by sequencing diplomacy before force.
AI is changing the attack-defense asymmetry. Threat actors are using LLMs to scale reconnaissance and exploitation at machine speed, while most defensive operations still rely on human-oriented processes. The 15-day CISA patch window is becoming obsolete when AI frameworks can exploit thousands of devices in 10 minutes. Simultaneously, insider threats from trusted service providers are materializing in new ways, from ransomware negotiators feeding intel to threat actors to supply chain breaches at contractors like Telus and CGI Group.