Latest Cybersecurity News and Articles


APT28 Targeted European Entities Using Webhook-Based Macro Malware

23 February 2026
The Russia-linked state-sponsored threat actor tracked as APT28 has been attributed to a new campaign targeting specific entities in Western and Central Europe. The activity, per S2 Grupo's LAB52 threat intelligence team, was active between September 2025 and January 2026. It has been codenamed Operation MacroMaze. "The campaign relies on basic tooling and the exploitation of legitimate services

Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb

23 February 2026
Cybersecurity researchers have disclosed details of a new cryptojacking campaign that uses pirated software bundles as lures to deploy a bespoke XMRig miner program on compromised hosts. "Analysis of the recovered dropper, persistence triggers, and mining payload reveals a sophisticated, multi-stage infection prioritizing maximum cryptocurrency mining hashrate, often destabilizing the victim

US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach

23 February 2026
The Everest ransomware group has taken credit for a hacker attack on Vikor Scientific, now called Vanta Diagnostics. The post US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach appeared first on SecurityWeek.

Long Island Medium Star Theresa Caputo Meets Cybercrime Magazine – Live!

23 February 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Feb. 23, 2026 In 2024, Long Island Medium star Theresa Caputo slammed online scammers and begged fans not to send money to them. The reality star warned fans about many social media users impersonating her The post Long Island Medium Star Theresa Caputo Meets Cybercrime Magazine – Live! appeared first on Cybercrime Magazine.

Ukrainian Gets 5 Years in US Prison for Aiding North Korean IT Fraud

23 February 2026
Oleksandr Didenko sold the stolen identities of US citizens, allowing North Koreans to get hired using freelance work platforms. The post Ukrainian Gets 5 Years in US Prison for Aiding North Korean IT Fraud appeared first on SecurityWeek.

⚡ Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & More

23 February 2026
Security news rarely moves in a straight line. This week, it feels more like a series of sharp turns, some happening quietly in the background, others playing out in public view. The details are different, but the pressure points are familiar. Across devices, cloud services, research labs, and even everyday apps, the line between normal behavior and hidden risk keeps getting thinner. Tools

Autonomous AI Agents Provide New Class of Supply Chain Attack

23 February 2026
While this campaign targets crypto wallets and steals money, the methodology has far wider potential that could be used by other attackers.  The post Autonomous AI Agents Provide New Class of Supply Chain Attack appeared first on SecurityWeek.

How Exposed Endpoints Increase Risk Across LLM Infrastructure

23 February 2026
As more organizations run their own Large Language Models (LLMs), they are also deploying more internal services and Application Programming Interfaces (APIs) to support those models. Modern security risks are being introduced less from the models themselves and more from the infrastructure that serves, connects and automates the model. Each new LLM endpoint expands the attack surface, often in

Romanian Hacker Pleads Guilty to Selling Access to US State Network

23 February 2026
Catalin Dragomir admitted in a US court to selling access to an Oregon state government office’s network. The post Romanian Hacker Pleads Guilty to Selling Access to US State Network appeared first on SecurityWeek.

Hundreds of FortiGate Firewalls Hacked in AI-Powered Attacks: AWS

23 February 2026
Threat actors relying on AI have been exploiting exposed ports and weak credentials to take over FortiGate devices. The post Hundreds of FortiGate Firewalls Hacked in AI-Powered Attacks: AWS appeared first on SecurityWeek.

Recent RoundCube Webmail Vulnerability Exploited in Attacks

23 February 2026
Patched in December 2025, the exploited flaw leads to XSS attacks via the animate tags in SVG documents. The post Recent RoundCube Webmail Vulnerability Exploited in Attacks appeared first on SecurityWeek.

Mississippi Hospital System Closes All Clinics After Ransomware Attack

23 February 2026
A ransomware attack forced the University of Mississippi Medical Center to close all of its roughly three dozen clinics around the state and cancel elective procedures. The post Mississippi Hospital System Closes All Clinics After Ransomware Attack appeared first on SecurityWeek.

Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens

23 February 2026
Cybersecurity researchers have disclosed what they say is an active "Shai-Hulud-like" supply chain worm campaign that has leveraged a cluster of at least 19 malicious npm packages to enable credential harvesting and cryptocurrency key theft. The campaign has been codenamed SANDWORM_MODE by supply chain security company Socket. As with prior Shai-Hulud attack waves, the malicious code embedded

PayPal Data Breach Led to Fraudulent Transactions

23 February 2026
PayPal blamed an application error for the exposure of customer personal information for nearly 6 months.  The post PayPal Data Breach Led to Fraudulent Transactions appeared first on SecurityWeek.

MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

23 February 2026
The Iranian hacking group known as MuddyWater (aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targeted several organizations and individuals mainly located across the Middle East and North Africa (MENA) region as part of a new campaign codenamed Operation Olalampo. The activity, first observed on January 26, 2026, has resulted in the deployment of new malware families that share

Human-related security risks rose 90% in 2025

23 February 2026
2025 saw a rise in AI-related security risks.

41% of Organizations Have Hired a Fake Candidate

23 February 2026
Deepfakes are leading to fraudulent job positions and hirings.

AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries

21 February 2026
A Russian-speaking, financially motivated threat actor has been observed taking advantage of commercial generative artificial intelligence (AI) services to compromise over 600 FortiGate devices located in 55 countries. That's according to new findings from Amazon Threat Intelligence, which said it observed the activity between January 11 and February 18, 2026. "No exploitation of FortiGate

Critical Grandstream Phone Vulnerability Exposes Calls to Interception

21 February 2026
The flaw tracked as CVE-2026-2329 can be exploited without authentication for remote code execution with root privileges.  The post Critical Grandstream Phone Vulnerability Exposes Calls to Interception appeared first on SecurityWeek.

Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning

21 February 2026
Artificial intelligence (AI) company Anthropic has begun to roll out a new security feature for Claude Code that can scan a user's software codebase for vulnerabilities and suggest patches. The capability, called Claude Code Security, is currently available in a limited research preview to Enterprise and Team customers. "It scans codebases for security vulnerabilities and suggests targeted