Amazon Threat Intelligence reports a Russian-speaking, financially motivated actor leveraged commercial generative AI services to compromise over 600 FortiGate devices in 55 countries between January 11 and February 18, 2026. The case shows how GenAI can accelerate recon and intrusion workflows at scale, reducing attacker overhead. Defenders should audit FortiGate appliances for unauthorized changes, ensure current firmware/hardening, and rotate credentials.
Source: TheHackerNews
CISA Adds Two Actively Exploited Roundcube Flaws to KEV
Two Roundcube webmail vulnerabilities— including CVE-2025-49113 (CVSS 9.9) involving deserialization of untrusted data—were added to CISA’s Known Exploited Vulnerabilities catalog amid evidence of active attacks. KEV inclusion signals urgent remediation for government and private operators alike, especially where Roundcube is internet-exposed. Patch to supported versions and review logs for suspicious payloads or webshell activity.
Source: TheHackerNews
Unauthenticated RCE in Grandstream Phones Enables Call Interception
CVE-2026-2329 allows remote, unauthenticated attackers to achieve root-level code execution on affected Grandstream devices, potentially exposing voice traffic to interception. Organizations should apply vendor fixes immediately, restrict device exposure, disable remote management where possible, and segment VoIP from user networks.
Source: SecurityWeek
PayPal Confirms Breach: Personal Data Exposed, Fraudulent Transactions Reported
PayPal disclosed a prolonged breach that exposed customer information and enabled unauthorized transactions, prompting password resets. Users should enable two-factor authentication, set a new unique password, and monitor linked cards and bank accounts for any anomalies.
Source: Forbes Security
“ClickFix” Fake Captcha Campaign Drops Infostealer for 25+ Browsers, Crypto Wallets
Researchers detail a stealthy ClickFix operation that lures users with fake captchas, then runs malicious PowerShell to deploy an infostealer targeting over 25 browsers, cryptocurrency wallets like MetaMask, and gaming accounts. Block unneeded PowerShell, deploy script-control policies, and train users to spot suspicious captcha prompts.
Source: HackRead
NATO Allies: Hospital Cyberattacks May Constitute Acts of War
According to new reporting, top NATO members increasingly view cyberattacks on hospitals as potential acts of war, even as they grapple with consistent response frameworks. With state-linked actors escalating operations against critical sectors, the policy debate foreshadows stronger deterrence measures and closer public–private coordination.
Source: Politico Cyber
New LOL Technique: Abusing sti_ci.dll’s InstallWiaDevice Export
Research highlights that Windows’ sti_ci.dll exposes an InstallWiaDevice export that can be directly invoked, expanding prior DLL sideloading findings from 2017. The discovery adds another living-off-the-land avenue for execution and potential defense evasion. Monitor for anomalous use of InstallWiaDevice, enforce WDAC/AppLocker controls, and harden DLL search paths.
Source: Hexacorn
You May Also Be Interested In...
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
UK Council Faces Data Breach Claim After Mishandling Trans Complaints