Latest Internet & Cybersecurity News

📅February 12, 2026 at 1:00 PM
Microsoft's February 2026 Patch Tuesday fixes 54-61 vulnerabilities including six exploited zero-days; ransomware and extortion surge; CVE forecasts hit 50,000+; new stealers and OT guidance emerge.
1

Microsoft February 2026 Patch Tuesday Addresses 54 Vulnerabilities Including Six Zero-Days

Microsoft released patches for 54 vulnerabilities on February 10, 2026, including six zero-days actively exploited, such as CVE-2026-21510 (security feature bypass) and CVE-2026-21533 (Windows RDP privilege escalation).Source 1Source 2 CISA added these to its KEV catalog, urging immediate patching especially for RDP-exposed servers.Source 1Source 2 Reports vary slightly on total CVEs patched, up to 61.Source 10

2

SolarWinds Web Help Desk Flaw CVE-2025-40551 Actively Exploited for RCE

A critical unauthenticated RCE vulnerability in SolarWinds WHD (CVE-2025-40551) is under active exploitation, added to CISA's KEV catalog.Source 1 Attackers use vishing and smishing to gain initial access, then legitimate RMM tools for execution.Source 1 Targets include government and tech sectors with focus on domain controllers and cloud providers.Source 1

3

Muddled Libra Ransomware Campaign Evolves with Living-off-the-Land Tactics

Muddled Libra shifted to ransomware affiliates, using vishing/smishing and RMM tools to bypass EDR, targeting aviation, retail, and telcos.Source 1 Group compromises domain controllers, VMware vSphere, AWS, and Azure.Source 1 Minimizes malware use, exploiting human psychology for faster attacks.Source 1

4

RenEngine Campaign Deploys Stealers via Cracked Games to 400,000 Victims

Since March 2025, RenEngine loader in cracked games delivers HijackLoader, Lumma, and ACR Stealer, stealing credentials and crypto wallets globally.Source 1Source 4 Multi-stage chain affects over 400,000 victims.Source 1 Uses public IRC for C2 on compromised Linux systems.Source 1

5

FIRST Forecasts Over 50,000 CVEs in 2026, Potentially Up to 117,000

Cyber group FIRST predicts 59,000 median CVEs in 2026, surpassing 50,000 for first time, with 90% confidence up to 117,673.Source 3 Surge driven by broader software coverage and open-source components.Source 3 Three-year outlook shows sustained high volumes to 53,000+ in 2028.Source 3

6

Coinbase Cartel Ransomware Group Claims 60+ Victims with Data Theft Focus

Emerging since September 2025, Coinbase Cartel prioritizes data exfiltration over encryption, claiming over 60 victims.Source 4 Operations avoid system disruption to maximize extortion leverage.Source 4 Part of surging data-theft ransomware trend.Source 4

7

Intel 471: Extortion Breaches Surged 63% in 2025 to 6,800, Qilin Leads 2026

Extortion attacks rose 63% in 2025, peaking at 800+ breaches monthly from CLOP and Qilin campaigns.Source 6Source 8 Qilin dominates with 18% of victims, advancing coercion via data audits; expected top threat in 2026.Source 6 Supply chain hits include Cleo Harmony and Oracle EBS.Source 6

8

Global Cyber Attacks Rise in January 2026 with Ransomware and GenAI Risks

Check Point reports increased global attacks in January 2026, driven by ransomware surge and GenAI data exposure expansion.Source 7 Ransomware activity notably up amid broader threat landscape.Source 7 Highlights need for enhanced defenses against evolving tactics.Source 7

9

CISA Issues OT Security Guidance for Secure Communications in Critical Infrastructure

CISA advises phased adoption of signing, logging, and encryption for OT to counter MITM and unauthorized updates, addressing cost and complexity barriers.Source 9 Prioritize northbound traffic; start with signing before full enforcement.Source 9 Targets integrity of OT data in critical sectors.Source 9

10

LTX Stealer Targets Windows via Obfuscated Installers with Cloud Backend

New Node.js-based LTX Stealer harvests Chromium browser credentials and crypto data from Windows, using Supabase and Cloudflare for C2.Source 4 Distributed via obfuscated Inno Setup installers in large-scale campaign.Source 4 Focuses on credential and artifact exfiltration.Source 4

11

Ransomware Remains Top AI Threat in 2026 with $74 Billion Projected Costs

Cybersecurity Ventures lists ransomware among top 10 AI threats for 2026, predicting costs rise 30% to $74B from $57B in 2025.Source 5 AI enables malware, prompt injection, and evolved extortion beyond encryption.Source 5 Includes agentic AI and human-targeted attacks.Source 5

12

Pwn2Own Automotive Uncovers 76 Zero-Days in Vehicles and Chargers

Third annual Pwn2Own Automotive in Tokyo revealed 76 zero-days in Tesla IVI, EV chargers like Alpitronic, and Automotive Grade Linux.Source 4 Top teams earned up to $215,000; highlights automotive cyber risks.Source 4 Vulnerabilities in in-vehicle systems and OS.Source 4