Microsoft patch CVE-2026-26119 Privilege Escalation in Windows Admin Center

Ravi LakshmananFebruary 19, 2026Vulnerability/Network Security Microsoft has revealed that it has patched a security flaw in Windows Admin Center that could allow an attacker to escalate privileges. Windows Admin Center is a locally deployed, browser-based set of management tools that allows users to manage Windows clients, servers, and clusters without connecting to the cloud. The […]
OpenSSL RCE, Foxit 0-Days, Copilot Leak, AI Password Flaws & 20+ Stories

Ravie LakshmananFeb 19, 2026Cybersecurity / Hacking News The cyber threat space doesn’t pause, and this week makes that clear. New risks, new tactics, and new security gaps are showing up across platforms, tools, and industries — often all at the same time. Some developments are headline-level. Others sit in the background but carry long-term impact. […]
How the AI collapses the response window

We’ve all seen the situation where a developer deploys a new cloud workload and grants overly broad permissions just to keep the sprint moving forward. An engineer generated a “temporary” API key for testing and forgot to revoke it. Previously, these were small operational risks and liabilities that would eventually be repaid in a slower […]
Fake IPTV app spreads massive Android malware targeting mobile banking users

Ravi LakshmananFebruary 19, 2026Banking Malware / Mobile Security Cybersecurity researchers have revealed details of a new Android Trojan called Massiv that aims to facilitate device takeover (DTO) attacks for financial theft. According to ThreatFabric, the malware tricks victims by disguising itself as a seemingly harmless IPTV app, indicating that the activity primarily identifies users looking […]
CRESCENTHARVEST campaign targets Iranian protest supporters with RAT malware

Ravi LakshmananFebruary 19, 2026Cyber espionage/data security Cybersecurity researchers have revealed details of a new campaign dubbed CRESCENTHARVEST, which likely targets supporters of ongoing protests in Iran, carrying out information theft and long-term espionage operations. Acronis Threat Research Unit (TRU) announced that it had observed this activity since January 9th. The attack reportedly delivers a malicious […]
Citizen Lab finds Cellebrite tool used on mobile phone of Kenyan activist in police custody

Ravi LakshmananFebruary 18, 2026Mobile security/spyware A new study by Citizen Lab has found evidence that Kenyan authorities used a commercial forensic extraction tool made by Israeli company Celebrite to hack into the mobile phones of prominent dissidents, the latest incident of technology abuse targeting civil society. The Interdisciplinary Research Unit at the University of Toronto’s […]
Grandstream GXP1600 VoIP phone exposed to unauthenticated remote code execution

Ravi LakshmananFebruary 18, 2026Network Security/Enterprise Security Cybersecurity researchers have revealed a critical security flaw in Grandstream GXP1600 series VoIP phones that could allow attackers to seize control of susceptible devices. This vulnerability is tracked as CVE-2026-2329 and has a CVSS score of 9.3 out of a maximum of 10.0. This is described as a case […]
Critical flaws found in four VS Code extensions with over 125 million installs

Ravi LakshmananFebruary 18, 2026Vulnerabilities/Software Security Cybersecurity researchers have revealed multiple security vulnerabilities in four popular Microsoft Visual Studio Code (VS Code) extensions that, if successfully exploited, could allow threat actors to steal local files and execute code remotely. The extensions that have been installed over 125 million times in total are Live Server, Code Runner, […]
Operating in a Permanently Unstable World

Even in 2025, navigating the digital ocean still felt like a matter of direction. Organizations have plotted routes, watched the horizon, and adjusted course to reach the safe harbor of resilience, reliability, and compliance. In 2026, the sea is no longer calm between storms. Cybersecurity is currently unfolding amid conditions of continued atmospheric instability. AI-driven […]
Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 exploited since mid-2024

Ravi LakshmananFebruary 18, 2026Zero-day/vulnerabilities A maximum-severity security vulnerability in Dell RecoverPoint for Virtual Machines has been exploited as a zero-day by a suspected China-linked threat cluster known as UNC6201 since mid-2024, according to a new report from Google Mandiant and the Google Threat Intelligence Group (GTIG). This activity involves exploitation of CVE-2026-22769 (CVSS score: 10.0), […]