Heroes, your curated look at the current cybersecurity landscape for Feb 10, 2026.
Critical Threats
SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks
Microsoft reports that threat actors are actively exploiting internet-exposed SolarWinds Web Help Desk instances to gain initial access and move laterally through networks. This is a multi-stage intrusion campaign targeting unpatched help desk software.
Business Impact
Help desk systems often hold sensitive user data and credentials; a breach here facilitates rapid spread to high-value assets, leading to potential ransomware deployment and significant downtime.
Recommended Action
Direct IT to: "Immediately audit all SolarWinds Web Help Desk instances for internet exposure and apply the latest patches."
Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code Execution
Fortinet has patched a critical SQL injection vulnerability (CVSS 9.1) in FortiClientEMS that allows unauthenticated attackers to execute arbitrary code. This flaw essentially gives attackers a "master key" to the endpoint management server without needing a password.
Business Impact
Exploitation grants full control over the endpoint management server, allowing attackers to deploy ransomware to all managed clients or steal sensitive corporate data. Expect immediate operational paralysis and potential GDPR/SOX compliance violations if not patched.
Recommended Action
Ask your IT team: "Have we applied the latest security updates to our FortiClientEMS servers, specifically addressing CVE-2026-21643?"
BeyondTrust Fixes Critical Pre-Auth Bug Allowing Remote Code Execution
BeyondTrust has resolved a critical vulnerability (CVSS 9.9) in its Remote Support and Privileged Remote Access products that allows attackers to execute code remotely before authentication. This affects the very tools used to secure privileged access, turning a security asset into a liability.
Business Impact
A compromise here bypasses the "keys to the kingdom" security layer, allowing attackers to create rogue admin accounts or access critical infrastructure undetected. This poses a severe risk of intellectual property theft and long-term persistence in the network.
Recommended Action
Verify with Security Operations: "Are our BeyondTrust appliances isolated from the public internet, and has the patch for CVE-2026-1731 been applied immediately?"
Dutch Agencies Hit by Ivanti EPMM Exploit Exposing Employee Data
The Dutch Data Protection Authority and Council for the Judiciary confirmed a breach where attackers exploited Ivanti EPMM flaws to access employee contact data. This incident moves from theoretical risk to confirmed active exploitation against government entities.
Business Impact
For organizations using Ivanti EPMM, this signals a high probability of targeted attacks. The impact includes regulatory scrutiny (GDPR), loss of employee trust, and potential follow-on phishing attacks using the stolen contact data.
Recommended Action
Request a report: "Do we use Ivanti EPMM? If so, have we scanned for indicators of compromise similar to the Dutch agency breach?"
Warlock Ransomware Breaches SmarterTools Through Unpatched Server
The Warlock ransomware gang (Storm-2603) successfully breached SmarterTools by exploiting an unpatched SmarterMail instance. This highlights the speed at which ransomware groups weaponize known vulnerabilities against communication infrastructure.
Business Impact
Reliance on unpatched communication servers creates a direct entry point for ransomware, resulting in total data encryption, operational blackout, and potential extortion demands.
Recommended Action
Ask Infrastructure teams: "Are all our mail servers, specifically SmarterMail if used, running the latest versions?"
High Severity
Flaw in Anthropic Claude Extensions Can Lead to RCE in Google Calendar
LayerX researchers discovered a flaw in Anthropic's Claude Desktop Extensions that allows threat actors to inject Remote Code Execution vulnerabilities into Google Calendar. This demonstrates the emerging risk of granting AI models full system privileges and API access.
Business Impact
As organizations rush to adopt AI tools, unvetted extensions can bypass traditional security controls, allowing attackers to manipulate corporate schedules or execute code via trusted applications.
Recommended Action
Review AI usage policy: "Are we restricting which extensions can be installed on corporate AI tools like Claude?"
Google Warns Over 1 Billion Android Phones Are Now at Risk
Google has issued a warning that over 40% of Android devices (1 billion+) are no longer receiving security updates. These devices are permanently exposed to known malware and spyware without a path for remediation.
Business Impact
Employees accessing corporate data from outdated personal Android devices introduce a massive, unpatchable attack surface into the enterprise environment.
Recommended Action
Audit BYOD policy: "Do our MDM policies block access from Android devices running unsupported OS versions?"
China-linked APT UNC3886 Targets Singapore Telcos
A cyber espionage campaign attributed to the China-linked group UNC3886 has targeted Singapore's telecommunications sector. This aligns with broader geopolitical trends of state-sponsored actors targeting critical infrastructure providers.
Business Impact
Telecom breaches can lead to interception of sensitive corporate communications and metadata, compromising trade secrets and executive communications.
Recommended Action
For regional operations: "Review threat intelligence feeds for UNC3886 indicators if we have operations in Southeast Asia."
Vulnerability Found in InsightVM & Nexpose: CVE-2026-1814 (FIXED)
ZAST.AI Raises $6M to Scale Zero False Positive AI-Powered Code Security
ZAST.AI has secured funding to scale its AI-powered code security solution. This investment reflects the growing market necessity for tools that can secure the AI and machine learning supply chain against emerging threats.
Other Noteworthy
Vulnerability Found in InsightVM & Nexpose: CVE-2026-1814 (FIXED)
ZAST.AI Raises $6M to Scale Zero False Positive AI-Powered Code Security
ZAST.AI has secured funding to scale its AI-powered code security solution. This investment reflects the growing market necessity for tools that can secure the AI and machine learning supply chain against emerging threats.
Vendor Spotlight
Protect AI (Specialized Vendor)
Specialization: AI Security and MLSecOps
Why Protect AI Today: The provided threat landscape highlights the emergence of AI-specific security solutions, specifically the funding news for ZAST.AI. Protect AI is a direct leader in this emerging sector, providing necessary tools to secure the machine learning supply chain and AI models against vulnerabilities, paralleling the need to patch traditional software flaws like those listed for Fortinet and BeyondTrust.
Key Capability: AI Security Posture Management (AISPM) to detect vulnerabilities in ML models, notebooks, and datasets.
Recommended Actions: 1. Navigate to Guardian Console → Scans → Create New Scan → Select Repository/Model 2. Navigate to Radar Console → Policy Management → Admission Control → Create Policy 3. Navigate to Radar Console → Inventory → Select Model → View AI-BOM
Verification Steps: - Review the 'Scan History' log in the Guardian Dashboard - Simulate a deployment of a model containing a known EICAR test string or known CVE
Detection & Response
⚠️ Disclaimer: Test all detection logic in non-production environments before deployment.
1. Vendor Platform Configuration - Protect AI
2. YARA Rule for Suspicious Artifacts (Generic)
3. SIEM Query — Fortinet SQLi Attempt Detection (CVE-2026-21643)
4. PowerShell Script — Check SolarWinds WHD Service Status
This rundown should provide a solid overview of the current threat landscape. Thank you to all our cyberheroes for your diligence and hard work. Stay vigilant!