Amazon Threat Intelligence reports a Russian-speaking actor used off-the-shelf generative AI tools to rapidly discover exposed management ports and weak credentials, taking over more than 600 FortiGate devices in five weeks. The incident underscores how cheaply available AI is accelerating reconnaissance and exploitation workflows, and why closing management interfaces, enforcing MFA, and hardening credentials on perimeter appliances are critical now.
Source: The Record
Actively exploited BeyondTrust flaw (CVE-2026-1731) targets remote access and privilege pathways
Attackers are exploiting a critical 9.9 CVSS vulnerability in BeyondTrust Remote Support and Privileged Remote Access to deploy VShell, gain persistence, and move laterally. Organizations should patch immediately, restrict external access to these systems, audit for unauthorized users and services, and rotate credentials used through the affected platforms.
Source: Security Affairs
CISA’s new directive sets deadlines to inventory and replace unsupported edge devices
CISA’s Binding Operational Directive 26-02 requires federal agencies to identify, report, decommission, and replace unsupported edge gear (firewalls, routers, switches, load balancers, WAPs) on firm timelines. Unsupported devices don’t receive patches and are high-risk ingress points; agencies must inventory them within three months and plan accelerated replacement to reduce exposure.
Source: Help Net Security
Lazarus-linked operators deploy Medusa ransomware against U.S. healthcare and Middle East targets
Researchers observed North Korea’s Lazarus group using Medusa ransomware in recent intrusions, including against a U.S. healthcare organization and a Middle Eastern firm. The activity highlights ongoing blending of state-backed tradecraft with financially motivated extortion, raising the stakes for critical sectors with low outage tolerance.
Source: The Record
Ransomware hits Japanese chip-testing giant Advantest, spotlighting semiconductor supply-chain risk
Advantest confirmed a ransomware incident after detecting unusual IT activity on February 15. As a key supplier of semiconductor test equipment globally, the breach raises concerns over downstream impacts on electronics, mobile, and AI manufacturing ecosystems dependent on timely production and support.
Source: Help Net Security
RoundCube webmail XSS (patched in Dec 2025) now exploited in the wild
Threat actors are leveraging an SVG animate tag XSS flaw in RoundCube that was fixed late last year, enabling script execution via crafted messages. Admins should ensure instances are updated to patched versions, review webmail gateway filtering for malicious SVG content, and check server logs for signs of exploitation.
Source: SecurityWeek
PayPal application error exposed customer data for months, fueling fraudulent transactions
PayPal said a coding issue in its Working Capital loan system led to the long-running exposure of customer personal information that attackers abused for fraud. Impacted businesses should monitor for suspicious charges, rotate API keys, and validate access controls around fintech integrations where shared data may persist.
Source: SecurityWeek
You May Also Be Interested In...
Fake Zoom meeting “update” silently installs surveillance software
Energy Department patched flaws enabling email impersonation in critical minerals system
Fake troubleshooting tip on ClawHub leads to infostealer infection