Google collaborates with Russian actor suspect in failed malware attack on Ukrainian organization

Ravi LakshmananFebruary 13, 2026Threat Intelligence/Malware A previously undocumented attacker is believed to have targeted organizations in Ukraine using malware known as CANFAIL. The Google Threat Intelligence Group (GTIG) said the hacking group may have ties to Russian intelligence services. The attacker is assessed to be targeting defense, military, government, and energy organizations within local and […]
Google connects China, Iran, Russia, and North Korea to coordinate defense sector cyber operations

Ravi LakshmananFebruary 13, 2026Malware/Critical Infrastructure Research from the Google Threat Intelligence Group (GTIG) reveals that several state-sponsored, hacktivist, and criminal groups from China, Iran, North Korea, and Russia have set their sights on the Defense Industrial Base (DIB) sector. The tech giant’s threat intelligence division said hostile targets in this area are concentrated around four […]
UAT-9921 Deploys VoidLink malware targeting technology and financial sectors

Ravi LakshmananFebruary 13, 2026Cloud security/cyber espionage According to Cisco Talos findings, an unknown threat actor previously tracked as UAT-9921 was observed leveraging a new modular framework called VoidLink in campaigns targeting the technology and financial services sectors. “This threat actor appears to have been active since 2019, but has not necessarily been using VoidLink during […]
Malicious Chrome extension discovered to be stealing business data, email, and browsing history

Cybersecurity researchers have discovered a malicious Google Chrome extension designed to steal data related to Meta Business Suite and Facebook Business Manager. The extension, named CL Suite by @CLMasters (ID: jkphinfhmfkckkcnifhjiplhfoieffl), is marketed as a way to collect Meta Business Suite data, remove verification pop-ups, and generate two-factor authentication (2FA) codes. This extension has 33 […]
npm updates and considerations to strengthen your supply chain

hacker newsFebruary 13, 2026Supply Chain Security/DevSecOps In December 2025, in response to the Sha1-Hulud incident, npm completed a major certification review aimed at reducing supply chain attacks. While this overhaul is a solid step forward, this change does not make npm projects immune to supply chain attacks. npm remains susceptible to malware attacks – here’s […]
Researchers observe real-world exploitation of BeyondTrust CVSS 9.9 vulnerability

According to watchTowr, threat actors have begun exploiting recently revealed critical security flaws affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) products. “Overnight, we observed the first real-world exploitation of BeyondTrust across our global sensors,” Ryan Dewhurst, head of threat intelligence at watchTowr, said in a post on X. “The attacker is abusing […]
Google reports state-sponsored hackers are using Gemini AI to support reconnaissance and attacks

Ravi LakshmananFebruary 12, 2026Cyber espionage/artificial intelligence Google announced Thursday that it observed a North Korea-linked threat actor known as UNC2970 using its generative artificial intelligence (AI) model Gemini to conduct reconnaissance on targets. This is because various hacker groups continue to weaponize this tool to accelerate various stages of the cyberattack lifecycle, enable information manipulation, […]
Lazarus campaign plants malicious packages in npm and PyPI ecosystem

Cybersecurity researchers discovered a set of malicious packages across npm and Python Package Index (PyPI) repositories linked to a fake recruitment-themed campaign organized by the North Korean-linked Lazarus Group. This coordinated campaign is codenamed graphalgo, after the first package published on the npm registry. It is rated as being active since May 2025. “Developers are […]
AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories

Ravie LakshmananFeb 12, 2026Cybersecurity / Hacking News Threat activity this week shows one consistent signal — attackers are leaning harder on what already works. Instead of flashy new exploits, many operations are built around quiet misuse of trusted tools, familiar workflows, and overlooked exposures that sit in plain sight. Another shift is how access is […]
Why 84% of security programs are late

hacker newsFebruary 12, 2026Enterprise Security/Breach Prevention A new 2026 market intelligence survey of 128 enterprise security decision makers (available here) reveals a clear chasm forming between organizations. It has nothing to do with budget size or industry and everything to do with deciding on one framework. Organizations that implement Continuous Threat Exposure Management (CTEM) see […]