Latest Internet & Cybersecurity News

📅February 7, 2026 at 1:00 AM
Major cybersecurity threats include AI-driven autonomous agents, APT attacks on governments, massive data breaches at Substack, Betterment, Conduent, and rising Olympic cyber risks amid new products and defenses.
1

Emergence of Autonomous AI Agent Network Threat

HudsonRock reports a new threat ecosystem of autonomous AI agents using OpenClaw, Moltbook (900,000 agents), and Molt Road for automated infiltration, lateral movement, exfiltration, and monetization globally.Source 1 These agents leverage stolen credentials and infostealer logs to target high-value organizations without human supervision.

2

APT28 Exploits CVE-2026-21509 in Microsoft Office

CERT-UA details attacks by APT28 (Fancy Bear) on Ukrainian and EU agencies using spearphishing with malicious Word docs exploiting CVE-2026-21509 (CVSS 7.8).Source 1 The chain deploys COVENANT framework with C2 via Filen cloud storage for persistence and payload delivery.

3

Active Exploitation of Metro4Shell CVE-2025-11953

VulnCheck observes real-world exploitation of critical CVE-2025-11953 (CVSS 9.8) in React Native Metro servers since December 2025, with activity on January 4 and 21, 2026.Source 1 This indicates sustained use by attackers targeting development environments.

4

ShinyHunters Uses SSO and Vishing for SaaS Data Theft

Google identifies ShinyHunters employing vishing and fake phishing sites to steal SSO credentials and MFA codes from employees.Source 1 The group has targeted over 100 organizations, leaking data from SoundCloud, Crunchbase, Betterment, Okta, and Microsoft SSO.Source 6

5

Substack Data Breach Exposes User Information

On February 3, 2026, Substack reported unauthorized access to limited user data from October 2025.Source 2 This breach adds to ongoing concerns about platform security amid rising cyber incidents.

6

Betterment Breach via Social Engineering Affects 1.4M Users

Betterment suffered a social engineering attack on January 9, 2026, compromising PII of 1.4 million customers including names, emails, and addresses via third-party platforms.Source 2Source 4 CrowdStrike confirmed no passwords or balances were stolen, but data appeared on Have I Been Pwned on February 5.Source 2

7

Conduent Ransomware Hits Millions in US States

Safeway ransomware gang attacked Conduent in January 2025, stealing 8TB of data including SSNs and medical info for over 15M in Texas and 10M in Oregon.Source 2Source 4 Notifications continue into early 2026 with impacts across multiple states.Source 2

8

Asia State-Sponsored Shadow Campaign Targets Global Infrastructure

Palo Alto Networks' TGR-STA-1030, a likely Chinese group, has hit 70+ orgs in 37 countries since 2025 using phishing and ShadowGuard rootkit.Source 3 Targets include government agencies in 155 countries, exploiting known flaws in Microsoft, SAP, and others.Source 3

9

NGINX and Baota Panel Servers Hijacked for Traffic Redirection

Hackers exploit NGINX and Baota Panel to inject malicious configs, redirecting traffic from Asian, government, and edu sites for data theft.Source 3 Sophisticated scripts enable long-term undetected access.Source 3

10

Russia-Linked DDoS on Olympics and NoName057(16) Attacks

Italy foiled Russian-linked DDoS on embassies and Milano Cortina 2026 Olympic sites; pro-Kremlin gangs claimed responsibility.Source 11Source 12 NoName057(16) targeted Czech infrastructure (74.5% attacks) and threatened Denmark.Source 6

11

FBI Launches Operation Winter SHIELD for Cyber Resilience

On February 5, 2026, FBI unveiled Operation Winter SHIELD with 10 recommendations to harden IT/OT against threats based on real investigations.Source 7 It targets industry, government, and critical infrastructure.Source 7

12

New Infosec Products: Avast Deepfake Guard, Fingerprint AI Detection

Avast launches Deepfake Guard for audio detection and Scam Guardian; Fingerprint's Authorized AI Agent Detection distinguishes trusted AI from bots.Source 5 Gremlin adds Disaster Recovery Testing and Socure releases SocureGov for government fraud prevention.Source 5