THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft fixes six actively exploited zero‑days in February Patch Tuesday

Microsoft’s latest Patch Tuesday addresses roughly 60 vulnerabilities, including six zero‑days already exploited in the wild across Windows, Office components, and core services. High‑impact issues include security feature bypasses in Windows Shell, MSHTML, and Word, plus local privilege escalations in Desktop Window Manager and Remote Desktop Services. Security teams should prioritize rapid deployment and monitor for post‑patch exploitation attempts on internet‑facing and high‑value endpoints.

Source: SecurityWeek


Singapore telcos breached in China‑linked UNC3886 cyber‑espionage campaign

Singapore’s four major telecom providers faced a coordinated intrusion by UNC3886, prompting “Operation Cyber Guardian” to limit the actor’s movement and harden networks. Authorities say no services were disrupted and no customer data was accessed, but the operation underscores persistent, stealthy targeting of core communications infrastructure.

Source: Help Net Security


Ivanti EPMM zero‑days exploited against Dutch government bodies

Dutch authorities confirmed that attackers exploited recently disclosed Ivanti Endpoint Manager Mobile (EPMM) flaws to breach the Data Protection Authority and the Council for the Judiciary, exposing employee contact data. The incidents highlight rapid weaponization of EPMM vulnerabilities and the urgency of patching or isolating affected devices.

Source: The Hacker News


New SSHStalker botnet hijacks 7,000 Linux systems using IRC C2 and legacy exploits

Researchers detail SSHStalker, a Linux botnet estimated to have compromised 7,000 hosts by chaining mass scanning, old kernel exploits, and IRC‑based command‑and‑control. The campaign blends log tampering, rootkit‑class tooling, and rapid propagation—reminding defenders that unpatched legacy weaknesses remain a high‑yield target at scale.

Source: SecurityWeek


Unpatched SolarWinds Web Help Desk instances under active attack

Internet‑exposed SolarWinds Web Help Desk (WHD) systems are being actively targeted for initial access, with intruders deploying legitimate remote access and DFIR tools, using living‑off‑the‑land techniques, and setting up reverse SSH shells to exfiltrate data. Organizations should urgently remediate WHD vulnerabilities and audit for silent persistence.

Source: Help Net Security


Critical pre‑auth RCE patched in BeyondTrust Remote Support and PRA

BeyondTrust fixed a critical vulnerability that allows unauthenticated remote code execution via crafted requests on Remote Support (RS) and Privileged Remote Access (PRA). Given the privileged nature of these tools and their exposure in many environments, immediate patching and review of access logs are strongly advised.

Source: SecurityWeek


Google–Intel audit flags severe Intel TDX flaw enabling full compromise

A joint Google–Intel security review uncovered dozens of issues, including a severe vulnerability in Intel’s Trust Domain Extensions (TDX) that could allow full compromise of protected environments. The findings raise important questions for confidential computing users around threat models, update hygiene, and cloud platform readiness.

Source: SecurityWeek


You May Also Be Interested In...

Trojanized 7‑Zip downloads turn home computers into proxy nodes

New threat actor, UAT‑9221, leverages VoidLink framework in campaigns

CISA adds six actively exploited Microsoft zero‑days to KEV list

Cybersecurity — February 11, 2026 | Briefing24