Latest Internet & Cybersecurity News

๐Ÿ“…February 11, 2026 at 1:00 PM
Microsoft patches six actively exploited zero-days in February 2026 Patch Tuesday; Chinese spies hit Singapore telcos, new ransomware surges, and AI cyber risks escalate globally.
1

Microsoft February 2026 Patch Tuesday Fixes Six Actively Exploited Zero-Days

Microsoft released updates addressing 60 vulnerabilities, including six actively exploited zero-days like CVE-2026-21510, CVE-2026-21513, and CVE-2026-21525 in Windows components.Source 1Source 3Source 8 Experts urge immediate patching as these bypass protections and enable attacks via malicious attachments or denial-of-service.Source 1Source 10 SAP also issued 27 notes with two critical flaws.Source 1

2

Chinese Cyberspies UNC3886 Infiltrate Singapore's Major Telcos

China-linked group UNC3886 exploited zero-day firewall vulnerabilities to access Singapore's four largest telecoms, deploying rootkits for persistence.Source 2 Attackers exfiltrated technical network data for reconnaissance but no customer data was stolen, thanks to national response.Source 2 This highlights ongoing state-sponsored espionage in telecoms.Source 2

3

Ivanti EPMM Critical Vulnerabilities Exploited by Threat Groups

Threat actors used CVE-2026-1281 and CVE-2026-1340 for unauthenticated RCE on Ivanti Endpoint Manager Mobile, exposing employee data.Source 2Source 14 Governments and others are targeted in widespread attacks.Source 14 Exposed data includes names, emails, and phone numbers.Source 2

4

New Ransomware Group 0APT Claims 90+ Victims in Days

Emerging ransomware 0APT surged with 91 claimed victims in two days, targeting transportation, tech, and finance sectors.Source 4 Activity spike raises suspicions of credibility, exceeding even top groups like Qilin.Source 4 Victims reported rapidly in early February 2026.Source 4

5

Odyssey Stealer Targets macOS Users Worldwide

Infostealer malware Odyssey Stealer surges globally via fake CAPTCHA pages, expanding from US, France, Spain to North America, Latin America, Europe, Asia, and Africa.Source 6 Deployed through social engineering to steal information from macOS systems.Source 6 Threat actors use it for broad data theft campaigns.Source 6

6

La Sapienza University Hit by Major Cyberattack

Europe's largest university, La Sapienza in Rome, suffered IT disruption from cyberattack, shutting down networks.Source 6 Attackers exfiltrated 45 GB of student/staff data including IDs, health records, diplomas, and finances.Source 6 Recovery ongoing with task force formed.Source 6

7

Bitsight Launches Dark Web Intelligence for Supply Chains

Bitsight introduced real-time dark web monitoring for supply chain threats, mapping to third-party exposures for early warnings.Source 5 Helps security teams prioritize risks across vendor ecosystems.Source 5 Announced February 10, 2026.Source 5

8

Vectra AI Report: Cyber Resilience Lags in AI Era

2026 State of Threat Detection report shows security teams lack confidence in detecting threats despite AI investments.Source 7 Gaps persist in visibility and response, stalling resilience.Source 7 Highlights need for better risk signals.Source 7

9

Palo Alto Networks Completes CyberArk Acquisition

Palo Alto Networks acquired CyberArk to extend privilege security to all identities, including AI, reducing breach response time by 80%.Source 9 Addresses identity-based attacks in AI era.Source 9 Enhances platform for human, machine, AI controls.Source 9

10

CISA Alerts on OT Vulnerabilities After Poland Energy Attack

CISA issued alerts on operational technology flaws following attack on Poland energy sector damaging RTUs and wiping HMI data.Source 12 Urges patching critical OT systems.Source 12 Part of broader industrial cyber threats.Source 12

11

Citi Warns of Multi-Trillion Dollar Quantum Cyber Threat

Quantum attacks on systems like Fedwire could risk $2-3.3 trillion US GDP via 'harvest now, decrypt later'.Source 13 High-risk sectors include finance, healthcare, energy.Source 13 Calls for massive cryptography upgrade.Source 13

12

AI Agent Platform Exposes 1.5M Tokens in Misconfiguration

Database leak reveals 1.5 million API tokens and 35,000 emails; vulnerable to prompt injection and dominated by bots, scams.Source 2 88:1 bot-to-human ratio signals 'Dead Internet' risks.Source 2 Agents can be weaponized for data exfiltration.Source 2