Cybersecurity News Weekly: PayPal Breach, Chrome 0-Day, BeyondTrust RCE Exploit, and More
This article provides a summary of the significant cybersecurity events that occurred between Fri, Feb 16, 2026, and Thu, Feb 22, 2026, focusing on threats, attacks, breaches, and vulnerabilities.
This article provides a summary of the significant cybersecurity events that occurred between Fri, Feb 16, 2026, and Thu, Feb 22, 2026, focusing on threats, attacks, breaches, and vulnerabilities.
The week began with updates on the Noodlophile information stealer, which has evolved its attack strategies. The operators, linked to the Vietnamese group UNC6229, are now using fake job postings to target various individuals and deploy multi-stage stealers and RATs via DLL sideloading. Enhanced obfuscation techniques are being employed, including djb2 hashing and XOR encoding. Read More
A new Linux malware framework named VoidLink has emerged, showcasing AI-assisted threat development. It targets multiple cloud platforms and includes kernel-level rootkit capabilities. Read More
Threat actors are now utilizing Grok and Microsoft Copilot as covert channels for malware communication, bypassing traditional detection methods. Read More
Researchers have identified 200 unique domains associated with the Raspberry Robin operation, active since 2019 and spreading via infected USB drives. These domains are difficult to track due to their Fast Flux behaviors. Read More
A critical RCE vulnerability in BeyondTrust appliances has been actively exploited, with a single IP responsible for most attempts. Read More
Over 600 FortiGate devices were compromised using AI services, marking a significant case of AI-enabled offensive operations. Read More
Cloudflare experienced a global outage on Tue, Feb 21, 2026, due to a password rotation error. Read More
The Hellcat ransomware group breached Ascom's ticketing system, exfiltrating 44GB of data, including sensitive information. Read More
PayPal disclosed a breach exposing customers' sensitive information, increasing the risk of identity theft. Read More
The week began with updates on the Noodlophile information stealer, which has evolved its attack strategies.
SpyX confirmed a breach affecting nearly 2 million users, with exposed Apple Account credentials. Read More
California Cryobank reported a data breach exposing customer PII, executed via SQL injection. Read More
Significant vulnerabilities were disclosed this week. A summary of key findings is presented below:
CVE ID CVSS Affected Product Description Link
CVE-2026-1281 9.8 Critical Ivanti EPMM RCE actively exploited; single IP responsible for 83% of attacks Read More
CVE-2026-20140 High Splunk Enterprise for Windows Session hijacking via crafted requests Read More
CVE-2025-26909 9.6 Critical WP Ghost Plugin (200k+ sites) Unauthenticated LFI → RCE Read More
CVE-2025-26512 9.9 Critical NetApp SnapCenter Server Authenticated privilege escalation to remote admin Read More
N/A Critical Ivanti EPMM (Zero-Day) Two critical zero-days affecting enterprise MDM infrastructure Read More
N/A Critical Windows Admin Center Privilege escalation enabling full system takeover Read More
N/A High OpenClaw AI Framework Log Poisoning flaw injecting malicious data into AI agent logs Read More
N/A Critical better-auth API Keys Plugin Authentication bypass allowing unauthorized privilege escalation Read More
N/A High DrayTek Routers Active exploitation linked to ISP-wide router reboot loops Read More
Google released an emergency Chrome update to address a high-severity heap buffer overflow flaw. Read More
GitLab issued patches for multiple high-severity flaws in their Community and Enterprise editions. Read More
Based on reporting by Cyber Security News.
