THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
AI-Assisted Campaign Hits 600+ FortiGate Devices Across 55 Countries

Amazon Threat Intelligence reports a Russian-speaking, financially motivated actor leveraged commercial generative AI services to compromise over 600 FortiGate devices in 55 countries between January 11 and February 18, 2026. The case shows how GenAI can accelerate recon and intrusion workflows at scale, reducing attacker overhead. Defenders should audit FortiGate appliances for unauthorized changes, ensure current firmware/hardening, and rotate credentials.

Source: TheHackerNews


CISA Adds Two Actively Exploited Roundcube Flaws to KEV

Two Roundcube webmail vulnerabilities— including CVE-2025-49113 (CVSS 9.9) involving deserialization of untrusted data—were added to CISA’s Known Exploited Vulnerabilities catalog amid evidence of active attacks. KEV inclusion signals urgent remediation for government and private operators alike, especially where Roundcube is internet-exposed. Patch to supported versions and review logs for suspicious payloads or webshell activity.

Source: TheHackerNews


Unauthenticated RCE in Grandstream Phones Enables Call Interception

CVE-2026-2329 allows remote, unauthenticated attackers to achieve root-level code execution on affected Grandstream devices, potentially exposing voice traffic to interception. Organizations should apply vendor fixes immediately, restrict device exposure, disable remote management where possible, and segment VoIP from user networks.

Source: SecurityWeek


PayPal Confirms Breach: Personal Data Exposed, Fraudulent Transactions Reported

PayPal disclosed a prolonged breach that exposed customer information and enabled unauthorized transactions, prompting password resets. Users should enable two-factor authentication, set a new unique password, and monitor linked cards and bank accounts for any anomalies.

Source: Forbes Security


“ClickFix” Fake Captcha Campaign Drops Infostealer for 25+ Browsers, Crypto Wallets

Researchers detail a stealthy ClickFix operation that lures users with fake captchas, then runs malicious PowerShell to deploy an infostealer targeting over 25 browsers, cryptocurrency wallets like MetaMask, and gaming accounts. Block unneeded PowerShell, deploy script-control policies, and train users to spot suspicious captcha prompts.

Source: HackRead


NATO Allies: Hospital Cyberattacks May Constitute Acts of War

According to new reporting, top NATO members increasingly view cyberattacks on hospitals as potential acts of war, even as they grapple with consistent response frameworks. With state-linked actors escalating operations against critical sectors, the policy debate foreshadows stronger deterrence measures and closer public–private coordination.

Source: Politico Cyber


New LOL Technique: Abusing sti_ci.dll’s InstallWiaDevice Export

Research highlights that Windows’ sti_ci.dll exposes an InstallWiaDevice export that can be directly invoked, expanding prior DLL sideloading findings from 2017. The discovery adds another living-off-the-land avenue for execution and potential defense evasion. Monitor for anomalous use of InstallWiaDevice, enforce WDAC/AppLocker controls, and harden DLL search paths.

Source: Hexacorn


You May Also Be Interested In...

Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning

UK Council Faces Data Breach Claim After Mishandling Trans Complaints

Password Managers Share a Hidden Weakness

Cybersecurity — February 22, 2026 | Briefing24