THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft Patch Tuesday: Six Zero‑Days Under Active Exploitation

Microsoft’s February update fixes 59 vulnerabilities, including six zero‑days already being exploited. Three of the zero‑days are security feature bypasses in MSHTML/Trident (CVE‑2026‑21513) and Word (CVE‑2026‑21514), raising the risk from malicious documents and links. Prioritize patching Windows and Office across endpoints and VDI, and review attack surface reduction rules.

Source: Help Net Security


Apple patches iOS/macOS zero‑day used in “extremely sophisticated” attacks

Apple shipped updates across iOS, iPadOS, macOS, tvOS, watchOS, and visionOS to fix CVE‑2026‑20700, a dyld memory corruption bug exploited for arbitrary code execution. Apple characterized the exploitation as part of an extremely sophisticated attack chain. Update devices immediately and enable rapid OS updating for high‑risk users.

Source: SecurityWeek


Ivanti EPMM: Active exploitation and “sleeper” webshells spotted

Following disclosure of critical pre‑auth flaw CVE‑2026‑1281, researchers observed mass scanning plus campaigns planting dormant in‑memory Java class loaders as “sleeper” webshells on unpatched EPMM instances. Some activity appears tied to initial access brokers staging future intrusions. Patch immediately, hunt for in‑memory persistence, rotate credentials, and consider rebuilds of compromised servers.

Source: Help Net Security


Google warns: State actors are abusing AI; model theft attempts on the rise

Google’s Threat Intelligence Group reports surging “distillation” model‑extraction attempts and growing misuse of LLMs by APTs for recon, phishing, and tooling. China‑linked APT31 was seen prompting Gemini to analyze vulnerabilities and WAF bypasses against U.S. targets; Google says it disrupted assets tied to multiple actors. Defenders should monitor AI API usage for extraction patterns, apply abuse controls, and treat model IP as a protected asset.

Source: Google Cloud Blog (Threat Intelligence)


Audit finds severe Intel TDX flaw enabling full trust‑domain compromise

A joint Google–Intel security review uncovered a severe vulnerability in Intel’s Trust Domain Extensions (TDX) that could allow full compromise of protected VMs, alongside dozens of other issues and hardening opportunities. Cloud providers and confidential‑computing users should track microcode and hypervisor updates, verify attestation workflows, and plan for patch windows.

Source: SecurityWeek


CISA alert after Russia‑linked OT attack in Poland’s power sector

After a Static Tundra/Berserk Bear attack impacted Poland’s energy infrastructure, CISA warned U.S. critical‑infrastructure operators to harden OT/ICS environments. Guidance emphasizes changing default credentials, tightening network segmentation, improving monitoring, and validating incident response playbooks that span IT and OT.

Source: SC Media


First malicious Outlook add‑in steals 4,000+ credentials via supply chain

Researchers uncovered “AgreeToSteal,” a takeover of an abandoned legitimate Outlook add‑in that was republished to deliver a phishing login flow through Microsoft’s own add‑in ecosystem. The campaign harvested more than 4,000 credentials before takedown. Audit and restrict third‑party add‑ins, enforce OAuth app governance/consent policies, and revoke affected tokens.

Source: Koi Security


You May Also Be Interested In...

Kimwolf Botnet Swamps Anonymity Network I2P — KrebsOnSecurity
Microsoft to Enable ‘Windows Baseline Security’ With New Runtime Integrity Safeguards — SecurityWeek
OWASP’s Vendor Criteria aims to cut through AI red‑teaming vendor noise — Help Net Security
Cybersecurity — February 12, 2026 | Briefing24