83% of Ivanti EPMM exploits are linked to a single IP on Bulletproof hosting infrastructure

Ravi LakshmananFebruary 12, 2026Vulnerability/Network Security A significant portion of exploitation attempts targeting newly revealed security flaws in Ivanti Endpoint Manager Mobile (EPMM) can be traced back to a single IP address on the bulletproof hosting infrastructure provided by PROSPERO. Threat intelligence firm GreyNoise announced that it recorded 417 exploit sessions from eight unique source IP […]
Fixes zero-day exploit affecting Apple, iOS, macOS, and Apple devices

Ravi LakshmananFebruary 12, 2026Zero-day/vulnerabilities Apple on Wednesday released updates to iOS, iPadOS, macOS Tahoe, tvOS, watchOS, and visionOS to address a zero-day flaw that the company says was exploited in a sophisticated cyber attack. The vulnerability is tracked as CVE-2026-20700 (CVSS score: N/A) and is described as a memory corruption issue in dyld, Apple’s dynamic […]
First malicious Outlook add-in discovered that steals over 4,000 Microsoft credentials

Cybersecurity researchers have discovered that this is the first known malicious Microsoft Outlook add-in to be detected in the wild. In this unusual supply chain attack, detailed by Koi Security, an unknown attacker claimed a domain associated with a legitimate, now-abandoned add-in to serve up a fake Microsoft login page, stealing over 4,000 credentials in […]
APT36 and SideCopy launch cross-platform RAT campaign against Indian companies

Ravi LakshmananFebruary 11, 2026Cyber espionage/threat intelligence India’s defense sector and government-linked organizations have been targeted by multiple campaigns aimed at compromising Windows and Linux environments using remote access Trojans that can steal sensitive data and ensure continued access to infected machines. This campaign is characterized by the use of malware families such as Geta RAT, […]
Public training opens the door to crypto mining in Fortune 500 cloud environments

hacker newsFebruary 11, 2026Identity Security/Threat Exposure Deliberately vulnerable training applications are widely used for security education, internal testing, and product demonstrations. Tools like OWASP Juice Shop, DVWA, Hackazon, and bWAPP are designed to be insecure by default, so it helps to learn how common attack techniques work in a controlled environment. The problem is not […]
Microsoft patches 59 vulnerabilities, including 6 actively exploited zero-days

Microsoft on Tuesday released a security update that addresses 59 flaws across its software. This includes six vulnerabilities that are said to have been actually exploited. Of the 59 deficiencies, 5 are rated as ‘severe’, 52 are rated as ‘important’, and 2 are rated as ‘moderate’ severity. 25 of the patched vulnerabilities are classified as […]
SSHStalker botnet uses IRC C2 to control Linux systems via legacy kernel exploits

Ravi LakshmananFebruary 11, 2026Linux / Botnet Cybersecurity researchers have revealed details of a new botnet operation called SSHStalker that relies on the Internet Relay Chat (IRC) communication protocol for command and control (C2) purposes. “This toolset blends stealth helpers with legacy-era Linux exploits. Alongside log cleaners (utmp/wtmp/lastlog tampering) and rootkit-class artifacts, attackers maintain a large […]
North Korea-linked UNC1069 uses AI decoys to attack crypto organizations

A North Korea-related threat actor known as UNC1069 has been observed targeting the cryptocurrency sector to steal sensitive data from Windows and macOS systems, with the ultimate goal of facilitating financial theft. Google Mandiant researchers Ross Inman and Adrian Hernandez said, “This intrusion relied on social engineering schemes including compromised Telegram accounts, fake Zoom meetings, […]
North Korean agents impersonate experts on LinkedIn to infiltrate companies

Information technology (IT) employees associated with the Democratic People’s Republic of Korea (DPRK) are now applying for remote jobs using the real LinkedIn accounts of impersonated individuals, marking a new expansion of fraud. “These profiles often include verified work emails and ID badges, which North Korean operatives hope will make fraudulent applications appear legitimate,” the […]
Reynolds ransomware embeds BYOVD drivers that disable EDR security tools

Cybersecurity researchers have revealed details about an emerging ransomware family called Reynolds. This family includes a Bring Your Own Vulnerable Driver (BYOVD) component in the ransomware payload itself to evade defenses. BYOVD refers to an adversarial technique that exploits legitimate but flawed driver software to escalate privileges and disable endpoint detection and response (EDR) solutions, […]