THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
PromptSpy: Android malware abuses generative AI for persistence

ESET researchers uncovered PromptSpy, the first known Android malware to integrate generative AI into its execution flow. By prompting Google’s Gemini to guide malicious UI interactions, the malware achieves persistence and can capture lockscreen data, block uninstalls, gather device info, take screenshots, and record screen activity. The finding marks a new milestone in mobile threat tradecraft, where AI is used operationally rather than just for payload generation.

Source: ESET Blog


Ivanti exploitation surges; zero-day activity traced back to July 2025

Security researchers report a sharp rise in exploitation of Ivanti flaws, with evidence that zero-day activity dates to July 2025. Attackers have been using the bugs to deliver shells, conduct reconnaissance, and download malware—underscoring the need for thorough log review and post-patch compromise checks in environments that exposed affected devices.

Source: SecurityWeek


Critical Grandstream VoIP flaw enables RCE and call interception (CVE-2026-2329)

A critical vulnerability in Grandstream VoIP phone web APIs allows remote attackers to take full control of devices and intercept calls. Rapid7 attributes the bug to improper bounds checking in a default-accessible management endpoint, creating a stealthy foothold risk on corporate networks that rely on these phones.

Source: Help Net Security


Microsoft discloses Windows Admin Center privilege escalation (CVE-2026-26119)

Microsoft has publicly acknowledged a high-severity privilege-escalation flaw in Windows Admin Center, widely used to manage Windows servers, clusters, and AD-joined systems. Though patched in December 2025 (WAC v2511), the late disclosure signals long-tail risk for unpatched deployments and emphasizes updating management planes as a priority.

Source: Help Net Security


France’s national bank account registry breached; 1.2M accounts exposed

France’s Ministry of Economy confirmed unauthorized access to the FICOBA registry, exposing data related to approximately 1.2 million bank accounts. Attackers reportedly used stolen credentials belonging to an authorized civil servant to browse the database, accessing account details and associated personal information.

Source: SecurityWeek


FBI warns of ATM jackpotting spike: $20M lost in 2025

The FBI says more than 700 ATM jackpotting incidents occurred last year, causing over $20 million in losses, and confirms the decade-old Ploutus malware remains active in the wild. Since 2020, at least 1,900 such incidents have been recorded, highlighting the need for aggressive physical and logical controls across ATM fleets.

Source: SecurityWeek


Malvertising on Facebook pushes fake Windows 11 downloads to steal creds and crypto

Malwarebytes warns that adversaries are weaponizing Facebook ads to distribute password-stealing malware disguised as Windows 11 downloads. The campaigns target both consumer and enterprise users, aiming to siphon credentials and cryptocurrency wallets via convincing lures that bypass casual scrutiny.

Source: Malwarebytes Blog


You May Also Be Interested In...

CISA alerts to critical auth bypass in Honeywell CCTVs (CVE-2026-1670)

German Rail Giant Deutsche Bahn hit by large-scale DDoS attack

Windows Notepad RCE via malicious Markdown links (CVE-2026-20841)

Cybersecurity — February 20, 2026 | Briefing24