On 18 February 2026, security researchers at AlienVault released a comprehensive threat report that exposed a new and highly sophisticated spam campaign targeting government agencies and corporate organizations worldwide. The campaign leveraged the legitimate infrastructure of
Continue ReadingBlog
Dell RecoverPoint Zero-Day Exploitation Report
In a recent threat intelligence briefing released by Mandiant and Google Threat Intelligence Group (GTIG) on February 19, 2026, a high‑risk zero‑day vulnerability in Dell RecoverPoint for Virtual Machines (RPVM) – CVE‑2026‑22769 – was identified as
Continue ReadingTablet Conqueror Reveals Links Between Major Android Botnets
Executive Summary On February 17, 2026, Kaspersky’s SecureList published a detailed threat report titled The Tablet Conqueror and the Links Between Major Android Botnets. The study exposes a new firmware‑level Android backdoor, Keenadu, and demonstrates its
Continue ReadingQR Code Phishing Threats Across Web and Mobile
Executive Summary QR codes have become a staple of everyday interactions, from contactless payments to event check‑ins. However, their ubiquity also makes them an attractive vector for cybercriminals. Unit 42’s latest threat report, "Phishing on the Edge
Continue ReadingStorm 2603 Targets CVE 2026 23760 to Deploy Warlock Ransomware
Threat Overview ReliaQuest has identified a new campaign, codenamed Storm 2603, that exploits a critical vulnerability in SmarterMail (CVE 2026 23760) to stage the Warlock ransomware on internet facing mail servers. The attack chain demonstrates a
Continue ReadingAttacker Use of RMM Tools via Video Conference Lures
Threat Overview In a sophisticated phishing campaign that has been identified by Netskope Threat Labs and reported by AlienVault, threat actors are exploiting the ubiquity of video‑conference platforms such as Zoom, Microsoft Teams, and Google Meet
Continue ReadingRapid Exploitation of React2Shell by Multiple Threat Actors Case Study
On 2026-02-13, AlienVault released a comprehensive threat report titled Multiple Threat Actors Rapidly Exploit React2Shell: A Case Study of Active Compromise. The document details how a newly disclosed vulnerability in React Server Components—named React2Shell—was turned into
Continue ReadingBeyondTrust Remote Support Vulnerability Threatens Thousands Of Networks
Threat Overview On February 13, 2026, the security community was alerted to a critical vulnerability in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) appliances. The flaw, identified as CVE-2026-1731, enables unauthenticated attackers to execute
Continue ReadingNation State Actors Exploit Notepad Supply Chain
Notepad++ is one of the most widely used source‑code editors in the world, with millions of installations across government, industry and academia. Its popularity makes it an attractive target for attackers seeking to compromise large numbers
Continue ReadingWindows Remote Desktop Services Zero Day Exploitation In Progress
Windows Remote Desktop Services (RDS) has become a high‑profile target for threat actors following the discovery of the critical zero‑day vulnerability CVE‑2026‑21533. The flaw allows an attacker with local access to elevate privileges to SYSTEM, effectively
Continue Reading