Microsoft’s February update fixes 59 vulnerabilities, including six zero‑days already being exploited. Three of the zero‑days are security feature bypasses in MSHTML/Trident (CVE‑2026‑21513) and Word (CVE‑2026‑21514), raising the risk from malicious documents and links. Prioritize patching Windows and Office across endpoints and VDI, and review attack surface reduction rules.
Source: Help Net Security
Apple patches iOS/macOS zero‑day used in “extremely sophisticated” attacks
Apple shipped updates across iOS, iPadOS, macOS, tvOS, watchOS, and visionOS to fix CVE‑2026‑20700, a dyld memory corruption bug exploited for arbitrary code execution. Apple characterized the exploitation as part of an extremely sophisticated attack chain. Update devices immediately and enable rapid OS updating for high‑risk users.
Source: SecurityWeek
Ivanti EPMM: Active exploitation and “sleeper” webshells spotted
Following disclosure of critical pre‑auth flaw CVE‑2026‑1281, researchers observed mass scanning plus campaigns planting dormant in‑memory Java class loaders as “sleeper” webshells on unpatched EPMM instances. Some activity appears tied to initial access brokers staging future intrusions. Patch immediately, hunt for in‑memory persistence, rotate credentials, and consider rebuilds of compromised servers.
Source: Help Net Security
Google warns: State actors are abusing AI; model theft attempts on the rise
Google’s Threat Intelligence Group reports surging “distillation” model‑extraction attempts and growing misuse of LLMs by APTs for recon, phishing, and tooling. China‑linked APT31 was seen prompting Gemini to analyze vulnerabilities and WAF bypasses against U.S. targets; Google says it disrupted assets tied to multiple actors. Defenders should monitor AI API usage for extraction patterns, apply abuse controls, and treat model IP as a protected asset.
Source: Google Cloud Blog (Threat Intelligence)
Audit finds severe Intel TDX flaw enabling full trust‑domain compromise
A joint Google–Intel security review uncovered a severe vulnerability in Intel’s Trust Domain Extensions (TDX) that could allow full compromise of protected VMs, alongside dozens of other issues and hardening opportunities. Cloud providers and confidential‑computing users should track microcode and hypervisor updates, verify attestation workflows, and plan for patch windows.
Source: SecurityWeek
CISA alert after Russia‑linked OT attack in Poland’s power sector
After a Static Tundra/Berserk Bear attack impacted Poland’s energy infrastructure, CISA warned U.S. critical‑infrastructure operators to harden OT/ICS environments. Guidance emphasizes changing default credentials, tightening network segmentation, improving monitoring, and validating incident response playbooks that span IT and OT.
Source: SC Media
First malicious Outlook add‑in steals 4,000+ credentials via supply chain
Researchers uncovered “AgreeToSteal,” a takeover of an abandoned legitimate Outlook add‑in that was republished to deliver a phishing login flow through Microsoft’s own add‑in ecosystem. The campaign harvested more than 4,000 credentials before takedown. Audit and restrict third‑party add‑ins, enforce OAuth app governance/consent policies, and revoke affected tokens.
Source: Koi Security
You May Also Be Interested In...
Kimwolf Botnet Swamps Anonymity Network I2P — KrebsOnSecurityMicrosoft to Enable ‘Windows Baseline Security’ With New Runtime Integrity Safeguards — SecurityWeek
OWASP’s Vendor Criteria aims to cut through AI red‑teaming vendor noise — Help Net Security