Dutch authorities confirm Ivanti zero-day exploit exposed employee contact data

Ravi LakshmananFebruary 10, 2026Data breach/vulnerabilities The Dutch Data Protection Authority (AP) and the Council of Justice in the Netherlands have acknowledged that the two agencies (Rvdr) have revealed that their systems were affected by a cyberattack that exploited a recently disclosed security flaw in Ivanti Endpoint Manager Mobile (EPMM), according to a notice sent to […]
Fortinet patches critical SQLi flaw that allows unauthenticated code execution

Ravi LakshmananFebruary 10, 2026Vulnerability/Network Security Fortinet has released a security update to address a critical flaw affecting FortiClientEMS that could lead to the execution of arbitrary code on susceptible systems. This vulnerability is tracked as CVE-2026-21643 and has a CVSS rating of 9.1 out of a maximum of 10.0. Improper Disablement Vulnerability of Special Elements […]
China-linked UNC3886 targets Singapore’s telecom sector with cyber espionage

Ravi LakshmananFebruary 9, 2026Cyber espionage/virtualization Singapore’s Cyber Security Agency (CSA) revealed on Monday that a China-aligned cyber espionage group known as UNC3886 had targeted Singapore’s telecommunications sector. “UNC3886 has launched a deliberate, targeted and well-planned campaign against Singapore’s telecommunications sector,” the CSA said. “Singapore’s four major telecommunications operators (‘telcos’) – M1, SIMBA Telecom, Singtel and […]
SolarWinds Web Help Desk exploited by RCE in multi-stage attack against public servers

Ravi LakshmananFebruary 9, 2026Vulnerabilities / Endpoint Security Microsoft disclosed that it observed a multi-stage intrusion in which an attacker exploited an Internet-exposed SolarWinds Web Help Desk (WHD) instance to gain initial access and move laterally across an organization’s network to other high-value assets. That said, the Microsoft Defender Security Research Team is wondering whether this […]
AI Skill Malware, 31Tbps DDoS, Notepad++ Hack, LLM Backdoors and More

Ravie LakshmananFeb 09, 2026Hacking News / Cybersecurity Cyber threats are no longer coming from just malware or exploits. They’re showing up inside the tools, platforms, and ecosystems organizations use every day. As companies connect AI, cloud apps, developer tools, and communication systems, attackers are following those same paths. A clear pattern this week: attackers are […]
How top CISOs can overcome burnout and speed up MTTR without hiring more people

Why do SOC teams continue to burn out and miss SLAs despite spending millions on security tools? Routine triage piles up, senior experts are dragged into basic verification, MTTR rises, and stealth threats still have room to slip through. Top CISOs have found that this solution provides teams with faster and clearer evidence of action […]
Bloody Wolf uses NetSupport RAT in spear phishing campaign to target Russian Uzbekistan

Ravi LakshmananFebruary 9, 2026Threat Intelligence/Cyber Espionage The threat actor known as Bloody Wolf is said to be involved in a campaign targeting Uzbekistan and Russia, infecting systems with a remote access Trojan known as NetSupport RAT. Cybersecurity vendor Kaspersky is tracking this activity under the name “Stan Goulds.” This threat actor is known to have […]
TeamPCP worm exploits cloud infrastructure to build criminal infrastructure

Cybersecurity researchers warned of a “massive campaign” that systematically targets cloud-native environments and sets up malicious infrastructure for subsequent exploitation. The activity, observed around December 25, 2025 and described as “worm-driven,” leveraged the recently disclosed React2Shell (CVE-2025-55182, CVSS score: 10.0) vulnerability, as well as exposed Docker APIs, Kubernetes clusters, Ray dashboards, and Redis servers. This […]
BeyondTrust fixes critical pre-authentication RCE vulnerability in remote support and PRA

Ravi LakshmananFebruary 9, 2026Enterprise Security/Network Security BeyondTrust has released an update that addresses a critical security flaw affecting its Remote Support (RS) and Privileged Remote Access (PRA) products. Successful exploitation could lead to remote code execution. “Certain older versions of BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) contain a critical pre-authentication remote code […]
OpenClaw integrates VirusTotal scanning to detect malicious ClawHub skills

OpenClaw (formerly Moltbot and Clawdbot) announced that it is partnering with Google-owned VirusTotal to scan skills uploaded to ClawHub, a skills marketplace, as part of a broader effort to strengthen the security of its agent ecosystem. “All skills published to ClawHub are now scanned using VirusTotal’s threat intelligence, including our new Code Insight feature,” said […]