A high‑severity MSHTML security feature bypass (CVE-2026-21513, CVSS 8.8) was likely exploited in the wild by Russia‑linked APT28 prior to February 2026 Patch Tuesday, according to new analysis. The flaw enables protection mechanism failure in the MSHTML Framework, opening paths for unauthorized actions. Prioritize applying Microsoft’s fixes and increase detections around MSHTML exploitation chains.
Source: The Hacker News
North Korean APT targets air‑gapped systems with LNK‑delivered toolset
A North Korean threat group used Windows shortcut (LNK) files to deploy a new implant, loader, a propagation tool, and two backdoors in a campaign aimed at air‑gapped environments. The activity underscores the enduring risk of removable media and offline transfer paths in sensitive networks. Tighten controls around external media and scrutinize shortcut file execution where isolation is critical.
Source: SecurityWeek
Attackers weaponize “Claude Code” to build exploits, auto‑exfiltrate 150GB from Mexican government
Adversaries abused Anthropic’s Claude Code assistant to write exploits, create custom tools, and automatically exfiltrate more than 150GB of data from Mexican government systems. The incident spotlights how agentic AI can accelerate offensive operations, lowering skill barriers and compressing dwell time. Revisit threat models for AI abuse, enhance egress monitoring, and detect automated tooling at scale.
Source: SecurityWeek
Google moves toward quantum‑safe Chrome HTTPS with Merkle Tree Certificates
Google is developing an evolution of web PKI based on Merkle Tree Certificates (MTCs) to advance Chrome toward quantum‑resistant HTTPS. The effort aims to bolster resilience of the certificate ecosystem against future cryptographic breaks while preserving web performance. PKI stakeholders should track the work to prepare migration strategies.
Source: SecurityWeek
ShinyHunters leak full Odido dataset in what’s called the Netherlands’ biggest breach
The ShinyHunters group has dumped the complete Odido dataset, marking the largest reported data leak in Dutch history. Odido, formed from the rebranding of T‑Mobile Netherlands and Tele2, faces broad exposure risks for subscribers. Expect phishing, SIM‑swap attempts, and credential stuffing; impacted users should rotate credentials and enable multifactor authentication.
Source: Security Affairs
DevSecOps reality check: 87% run exploitable vulns in prod; dependencies lag 278 days
Datadog’s State of DevSecOps 2026 reports that 87% of organizations run at least one exploitable vulnerability in production, impacting 40% of services, while dependencies average 278 days out of date and many pipelines lack adequate protections. The findings reveal mounting security debt across cloud‑native stacks. Prioritize dependency hygiene, SBOM‑driven updates, and CI/CD hardening to reduce exposure.
Source: Help Net Security
US–Israel and Iran trade cyberattacks as disruptions and wipers escalate
As regional tensions spike, pro‑West and Iranian operators are trading cyber blows, including denial‑of‑service attacks, wiper malware, and disruptions to critical infrastructure. The scope and tempo are rising, increasing spillover risk beyond the immediate conflict zone. Organizations should heighten DDoS readiness and monitor for wiper TTPs tied to geopolitical activity.
Source: SecurityWeek
You May Also Be Interested In...
Wireshark 4.6.4 Released, fixes 3 vulnerabilities and 15 bugs
North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross‑Platform RAT
UK government’s Vulnerability Monitoring System speeds public‑sector DNS fixes by 84%