CISA Adds Two Actively Exploited Round Cube Flaws to KEV Catalog

Ravi LakshmananFebruary 21, 2026Vulnerability/patch management The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws affecting the Roundcube webmail software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows. CVE-2025-49113 (CVSS score: 9.9) – Untrusted data deserialization vulnerability that allows remote […]
EC-Council Expands AI Certification Portfolio to Strengthen the Responsiveness and Security of U.S. AI Talent

With $5.5 trillion in global AI risks exposed and 700,000 U.S. workers in need of reskilling, four new AI certifications and the CISO v4 certification will help bridge the gap between AI adoption and workforce readiness. EC-Council, creator of the world-renowned Certified Ethical Hacker (CEH) credential and a global leader in applied cybersecurity education, today […]
BeyondTrust vulnerabilities used for web shells, backdoors, and data leaks

Ravi LakshmananFebruary 20, 2026Vulnerability/Cyber attack Threat actors are exploiting recently disclosed critical security flaws affecting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) products to This vulnerability is tracked as CVE-2026-1731 (CVSS score: 9.9) and allows an attacker to execute operating system commands in the context of a site user. In a report released […]
Cline CLI 2.3.0 Supply Chain Attack Installs OpenClaw on Developer Systems

In yet another software supply chain attack, the open-source artificial intelligence (AI)-powered coding assistant Cline CLI was updated to secretly install OpenClaw, a self-hosted autonomous AI agent that has become extremely popular over the past few months. “On February 17, 2026 at 3:26 AM PT, an unauthorized party published an update to the Cline CLI […]
ClickFix campaign exploits compromised sites to deploy MIMICRAT RAT

Rabi LakshmananFebruary 20, 2026Malware/Threat Intelligence Cybersecurity researchers have revealed details of a new ClickFix campaign that exploits compromised legitimate sites to deliver a previously undocumented remote access Trojan (RAT) called MIMICRAT (also known as AstarionRAT). “This campaign demonstrates a high level of operational sophistication, with compromised sites across multiple industries and geographies serving as the […]
New metrics shaping cyber insurance in 2026

hacker newsFebruary 20, 2026Cyber insurance / password security With one in three cyberattacks now involving the compromise of an employee account, insurance companies and regulators are placing great importance on identity posture when assessing cyber risk. However, for many organizations, these assessments remain largely opaque. Factors such as password hygiene, privileged access management, and multi-factor […]
Ukrainian citizen sentenced to 5 years in prison for North Korean IT worker fraud case

Ravi LakshmananFebruary 20, 2026Cybercrime/Law Enforcement A 29-year-old Ukrainian national has been sentenced to five years in prison in the United States for aiding North Korea’s information technology (IT) worker fraud scheme. In November 2025, Oleksandr “Alexandr” Dydenko pled guilty to wire fraud conspiracy and aggravated identity theft for stealing the identities of U.S. citizens and […]
Three former Google engineers charged with transferring trade secrets to Iran

Ravi LakshmananFebruary 20, 2026Insider Threat/Corporate Espionage Two former Google engineers and one of their husbands have been charged in the United States with stealing trade secrets from the search giant and other tech companies and transferring that information to unauthorized locations, including Iran. Samane Gandari, 41, and her husband Mohammad Javad Khosravi (also known as […]

[.] [.][.] Source link
Interpol Operation Red Card 2.0 arrests 651 people in African cybercrime crackdown

Ravi LakshmananFebruary 19, 2026Financial crime/Cyber crime As part of an effort led by law enforcement agencies from 16 African countries, an international cybercrime operation against online fraud resulted in the arrests of 651 people and the recovery of more than $4.3 million. The initiative, codenamed “Operation Red Card 2.0,” ran from December 8, 2025 to […]