Amazon Threat Intelligence observed that a Russian-speaking hacker used generative AI services to compromise over 600 FortiGate devices in 55 countries between January 11 and February 18, 2026. The attack did not exploit FortiGate vulnerabilities but targeted exposed management ports and weak, single-factor authentication, enabling a less-skilled attacker to exploit …
Read More »Amazon Report
French National Bank Account Registry Exposes 1.2M Bank AccountsÂ
The French national bank account registry was breached in late January 2026, with a potential exposure of 1.2 million accounts, according to a press release. A threat actor stole credentials from an official to access a database of bank accounts at French banks. The compromised data might include: Bank account …
Read More »Hackers exploiting Dell zero-day flaw (CVE-2026-22769) since mid-2024
A China-linked cyberespionage group has exploited a zero-day vulnerability in Dell’s RecoverPoint for Virtual Machines since at least mid-2024, according to Google’s Threat Intelligence Group and Mandiant. GTIG and Mandiant attributed the exploitation of CVE-2026-22769 to a group called UNC6201, who used the vulnerability for lateral movement, persistence, and deploying …
Read More »New ‘ZeroDayRAT’ Spyware Kit Allows Full Compromise of iOS and Android Devices
ZeroDayRAT is a new mobile spyware toolkit that allows remote access to Android and iOS devices, offering features like live camera feeds, keylogging, and theft of bank and crypto information. It is currently available via Telegram, and was first observed on February 2, 2026, and since analyzed by iVerify. It …
Read More »‘UNC3886’ breaches Singapore’s top four telcos
UNC3886 got accessed Singapore’s four main telecommunication providers—Singtel, StarHub, M1, and Simba—at least once last year. On 18 July 2025, Minister Mr. K Shanmugam announced that the APT group UNC3886 was found targeting our critical infrastructure, but no further details were provided for security reasons then. Recent investigations by the Cyber …
Read More »
ALERT
SystemBC Botnet Infects 10,000+ IPs & Government Networks
Researchers have discovered a large botnet made up of compromised devices that has infiltrated networks worldwide, including sensitive government systems. A report from Silent Push has identified over 10,000 unique IP addresses infected with SystemBC, a proxy malware used by cybercriminals to conceal their actions and deploy ransomware. The discovery …
Read More »Hackers Actively Exploiting SolarWinds Web Help Desk RCE Vulnerability
Attackers are quickly exploiting a remote code execution vulnerability in SolarWinds Web Help Desk, using compromised systems to deploy legitimate but misused administrative tools. Huntress observed that 84 endpoints in 78 partner organizations are using SolarWinds Web Help Desk, highlighting significant vulnerability. Huntress observed post-exploitation activity originating from a compromised …
Read More »China’s Salt Typhoon of espionage attacks: Norwegian intelligence discloses
Norway accused the hacker group Salt Typhoon of breaching various organizations. The Norwegian Police Security Service reports that the hacker group is targeting weak network devices for espionage. The disclosure was made in the Norwegian Police Security Service’s (PST) annual threat assessment for 2026. The agency’s director general, Beate GangÃ¥s, …
Read More »TGR-STA-1030 likely compromised Gov.t and CII in 37 Countries with BangladeshÂ
According to Palo Alto Networks, a state-backed hacking group compromised government and critical infrastructure systems worldwide. The security firm identifies the threat actor as TGR-STA-1030, and their recent activity is dubbed as the Shadow Campaign. Palo Alto Networks expressed high confidence that it’s a nation-state group operating out of Asia …
Read More »Less than10 Minutes: Hackers Gain AWS Admin Access Using AI
Sysdig Threat Research Team (TRT) observed an offensive cloud operation targeting an AWS environment in which the threat actor went from initial access to administrative privileges in less than 10 minutes. This incident was notable for its rapid execution and indications that the attacker used large language models (LLMs) to …
Read More »
InfoSecBulletin Cybersecurity for mankind