THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
China‑nexus hackers exploited Dell RecoverPoint zero‑day since 2024, deploy ‘GRIMBOLT’ and pivot with “Ghost NICs”

Mandiant and Google Threat Intelligence detailed ongoing exploitation of CVE-2026-22769 (CVSS 10.0) in Dell RecoverPoint for VMs by UNC6201. Attackers abused hardcoded Tomcat Manager credentials to deploy the SLAYSTYLE web shell and a new Native AOT-compiled backdoor dubbed GRIMBOLT, then pivoted into VMware environments using stealthy “Ghost NICs” and single‑packet authorization via iptables. Dell has issued remediations; organizations should patch immediately and review Tomcat logs, startup scripts, and appliance integrity for persistence.

Source: Google Threat Intelligence


Patch Chrome now: actively exploited zero‑day (CVE-2026-2441) allows code execution via malicious webpages

Google released an emergency Chrome update to fix the first actively exploited zero‑day of 2026, a use‑after‑free in CSS font feature handling that can enable remote code execution. Enterprises should expedite updates across all platforms and consider monitoring for suspicious browser child processes while stragglers patch.

Source: Malwarebytes Blog


Notepad++ fortifies updater after supply‑chain hijack used for targeted malware delivery

Following a sophisticated compromise of its update mechanism last year, Notepad++ 8.9.2 introduces a “double lock” design to harden update verification and block tampering. The maintainer says the changes make the process “effectively unexploitable,” a reminder for defenders to validate code‑signing, restrict updater egress, and monitor for anomalous update flows.

Source: The Hacker News


Keenadu: firmware‑level Android backdoor preinstalled on tablets from multiple brands

Kaspersky uncovered Keenadu, a backdoor inserted during the firmware build process and found in system apps and even Google Play‑distributed packages on some Android tablets. The malware can silently harvest data, seize app control, and is currently fueling ad‑fraud campaigns—underscoring the risk of compromised supply chains and the need for trusted ROMs, MDM controls, and post‑enrollment integrity checks.

Source: Securelist (Kaspersky)


Researchers show “zero‑knowledge” password managers can still be undermined via vault‑recovery design

A study from ETH Zurich and Università della Svizzera italiana found attack paths against Bitwarden, LastPass, and Dashlane that could expose vault contents if servers are compromised or recovery flows are abused. The work challenges blanket “we can’t see your data” claims by highlighting server‑influenced parameters and recovery mechanisms; users should enable phishing‑resistant MFA and minimize recovery options while vendors harden protocols.

Source: Ars Technica


OT risk intensifies: Dragos reports three new ICS‑focused groups in 2025; Volt Typhoon remains embedded in US energy

Dragos’ Year in Review highlights a maturing adversary focus on control‑loop mapping and persistent access to gateways and routers bridging IT and OT. The findings reinforce that internet‑facing gateways and remote access appliances can collapse the IT–OT boundary; operators should accelerate segmentation, harden edge gear, and expand continuous monitoring tailored to industrial protocols.

Source: SecurityWeek


Unit 42: Identity abuse drives most breaches as attackers traverse multiple surfaces with one credential

Palo Alto Networks’ Unit 42 found that a single stolen credential often opens paths across endpoints, cloud, SaaS, and identity planes, with 87% of cases spanning multiple attack surfaces. Organizations should prioritize phishing‑resistant MFA, conditional access and session controls, rapid credential revocation, and least‑privilege reviews to shrink blast radius.

Source: Help Net Security


You May Also Be Interested In... - CISA adds four actively exploited vulnerabilities to KEV catalog - European Parliament blocks AI tools on lawmakers’ devices over data exposure risks - SmartLoader uses trojanized Oura MCP server to drop StealC infostealer
Cybersecurity — February 18, 2026 | Briefing24