Latest Internet & Cybersecurity News

đź“…February 14, 2026 at 1:00 PM
Major cybersecurity threats include Singapore telecom espionage, BeyondTrust RCE exploits, new ransomware like Reynolds, state-sponsored AI-enhanced attacks, and Patch Tuesday fixes.
1

Singapore Confirms China-Linked Espionage Campaign Against Telecom Sector

Singapore disclosed an 11-month campaign by a China-linked group targeting its four major telecom operators using zero-day vulnerabilities in edge devices for long-term persistence.Source 1 The deliberate attack highlights blind spots in edge device security, urging defense-in-depth strategies.Source 1 Organizations should implement compensating controls for firewalls and similar devices.Source 1

2

Volvo and Flickr Disclose Third-Party Data Breaches

Volvo reported a breach affecting over 16,000 employees via a third-party cyberattack, while Flickr warned customers of increased phishing risks post-breach.Source 1 These incidents underscore supply chain vulnerabilities and the need for robust third-party risk management.Source 1 Business continuity plans must account for external dependencies.Source 1

3

Ivanti Mobile Management Vulnerability Breaches European Governments

An Ivanti vulnerability was exploited to breach European government entities, with sleeper shells implanted for persistent access.Source 1Source 7 Attackers uploaded payloads deliberately without immediate smash-and-grab tactics.Source 7 This follows patterns of mass exploitation in Ivanti products.Source 7

4

Active Exploitation of BeyondTrust CVE-2026-1731 RCE Vulnerability

CVE-2026-1731 in BeyondTrust Remote Support enables unauthenticated remote code execution; PoC released February 10 led to exploits within 24 hours.Source 3Source 5 Darktrace detected anomalous activities like beaconing and crypto mining across customers since then.Source 3 Past BeyondTrust breaches linked to nation-states, including U.S. Treasury.Source 3

5

Microsoft Patch Tuesday Fixes 59 Vulnerabilities, Including 6 Zero-Days

Microsoft's February patches address 59 flaws, with six zero-days under exploitation, notably CVE-2026-21510 for Windows Shell SmartScreen bypass.Source 1 SAP and Adobe also released critical patches for multiple products.Source 1 Vendors emphasize urgent updates to counter active threats.Source 1

6

New Reynolds Ransomware Uses BYOVD to Disable Security Tools

Reynolds ransomware embeds vulnerable drivers to bypass detection by Avast and Symantec, facilitating data theft and network hacks.Source 2 This BYOVD technique enhances stealth and organization among cybercriminals.Source 2 Combined with botnets like SSHStalker, it poses risks for DDoS and more.Source 2

7

State-Sponsored Hackers from China, NK, Iran Use Google Gemini AI for Attacks

Nation-state actors leverage Gemini AI for malware refinement, reconnaissance, and coding to enhance cyberattacks.Source 2Source 5 Google's GTIG reports usage in target intel gathering and automation.Source 2 International AI Safety Report notes GPAI aids vulnerability identification but not full autonomous attacks yet.Source 9

8

ZeroDayRAT Spyware Targets Android and iOS via Telegram Sales

New mobile spyware ZeroDayRAT sold openly on Telegram with dedicated support channels, first observed February 2.Source 7 iVerify identified the operational panel for buyers.Source 7 It represents evolving spyware platforms for mobile surveillance.Source 7

9

Threat Actors Hijack GitHub and LinkedIn Accounts for Malware and Insider Access

Hijacked GitHub accounts deliver backdoors to IT admins; DPRK uses stolen LinkedIn profiles for remote job infiltration.Source 1 This builds trust for malware distribution and insider threats.Source 1 OSINT researchers and admins are prime targets.Source 1

10

Tulsa International Airport Discloses Data Security Incident

Unauthorized access occurred January 17-20, 2026; TAIT secured systems and hired forensics after discovery.Source 4 Law enforcement notified; investigation ongoing with confidence in current security.Source 4 Affects airport improvement trust files.Source 4

11

Elastic Detects BADIIS Malware in Large-Scale SEO Poisoning on IIS Servers

Over 1,800 Windows IIS servers globally compromised for gambling ads via SEO poisoning, hitting governments and firms in multiple countries.Source 7 Monetized through illicit infrastructure webs.Source 7 Victims span Australia to Vietnam.Source 7

12

ScarCruft Evolves ROKRAT Malware Distribution with HWP OLE Dropper

North Korean-linked ScarCruft shifts to HWP OLE-based loaders from LNK chains, using Russian/Swiss clouds.Source 7 Enhances tradecraft for malware delivery.Source 7 Targets ongoing surveillance operations.Source 7