Mandiant and Google Threat Intelligence detailed ongoing exploitation of CVE-2026-22769 (CVSS 10.0) in Dell RecoverPoint for VMs by UNC6201. Attackers abused hardcoded Tomcat Manager credentials to deploy the SLAYSTYLE web shell and a new Native AOT-compiled backdoor dubbed GRIMBOLT, then pivoted into VMware environments using stealthy “Ghost NICs” and single‑packet authorization via iptables. Dell has issued remediations; organizations should patch immediately and review Tomcat logs, startup scripts, and appliance integrity for persistence.
Source: Google Threat Intelligence
Patch Chrome now: actively exploited zero‑day (CVE-2026-2441) allows code execution via malicious webpages
Google released an emergency Chrome update to fix the first actively exploited zero‑day of 2026, a use‑after‑free in CSS font feature handling that can enable remote code execution. Enterprises should expedite updates across all platforms and consider monitoring for suspicious browser child processes while stragglers patch.
Source: Malwarebytes Blog
Notepad++ fortifies updater after supply‑chain hijack used for targeted malware delivery
Following a sophisticated compromise of its update mechanism last year, Notepad++ 8.9.2 introduces a “double lock” design to harden update verification and block tampering. The maintainer says the changes make the process “effectively unexploitable,” a reminder for defenders to validate code‑signing, restrict updater egress, and monitor for anomalous update flows.
Source: The Hacker News
Keenadu: firmware‑level Android backdoor preinstalled on tablets from multiple brands
Kaspersky uncovered Keenadu, a backdoor inserted during the firmware build process and found in system apps and even Google Play‑distributed packages on some Android tablets. The malware can silently harvest data, seize app control, and is currently fueling ad‑fraud campaigns—underscoring the risk of compromised supply chains and the need for trusted ROMs, MDM controls, and post‑enrollment integrity checks.
Source: Securelist (Kaspersky)
Researchers show “zero‑knowledge” password managers can still be undermined via vault‑recovery design
A study from ETH Zurich and Università della Svizzera italiana found attack paths against Bitwarden, LastPass, and Dashlane that could expose vault contents if servers are compromised or recovery flows are abused. The work challenges blanket “we can’t see your data” claims by highlighting server‑influenced parameters and recovery mechanisms; users should enable phishing‑resistant MFA and minimize recovery options while vendors harden protocols.
Source: Ars Technica
OT risk intensifies: Dragos reports three new ICS‑focused groups in 2025; Volt Typhoon remains embedded in US energy
Dragos’ Year in Review highlights a maturing adversary focus on control‑loop mapping and persistent access to gateways and routers bridging IT and OT. The findings reinforce that internet‑facing gateways and remote access appliances can collapse the IT–OT boundary; operators should accelerate segmentation, harden edge gear, and expand continuous monitoring tailored to industrial protocols.
Source: SecurityWeek
Unit 42: Identity abuse drives most breaches as attackers traverse multiple surfaces with one credential
Palo Alto Networks’ Unit 42 found that a single stolen credential often opens paths across endpoints, cloud, SaaS, and identity planes, with 87% of cases spanning multiple attack surfaces. Organizations should prioritize phishing‑resistant MFA, conditional access and session controls, rapid credential revocation, and least‑privilege reviews to shrink blast radius.
Source: Help Net Security
You May Also Be Interested In... - CISA adds four actively exploited vulnerabilities to KEV catalog - European Parliament blocks AI tools on lawmakers’ devices over data exposure risks - SmartLoader uses trojanized Oura MCP server to drop StealC infostealer