Heroes, here's your curated threat landscape for Feb 12, 2026.
Critical Threats
Apple patches zero-day flaw that could let attackers take control of devices
Apple has released urgent security updates for iPhones, iPads, and Macs to fix a vulnerability in WebKit that is currently being exploited in the wild. This flaw allows attackers to execute arbitrary code simply by processing maliciously crafted web content.
Business Impact
If exploited, attackers could gain full control over executive or employee devices, leading to the theft of sensitive corporate data, credential harvesting, and potential entry into the corporate network via compromised endpoints.
Recommended Action
Ask your IT team: Have we enforced the latest iOS, iPadOS, and macOS updates across the entire mobile fleet today?
Nation-State Actors Exploit Notepad++ Supply Chain
Unit 42 has identified new infrastructure used by nation-state actors to compromise the popular text editor Notepad++. Attackers are likely using compromised plugins or distribution mirrors to deliver malware to developers and IT administrators.
Business Impact
Since Notepad++ is widely used by engineers with high-level access, a compromise here could provide attackers with "keys to the kingdom," leading to intellectual property theft or deep network infiltration.
Recommended Action
Ask your Security team: Do we have application allow-listing rules that verify the digital signatures of Notepad++ and its plugins before execution?
When AI Secrets Go Public: The Rising Risk of Exposed ChatGPT API Keys
Researchers found over 5,000 GitHub repositories and 3,000 live websites leaking hardcoded ChatGPT API keys. This exposure allows unauthorized actors to use paid AI resources at the victim's expense or access private AI model contexts.
Business Impact
Leaked keys can lead to massive unexpected financial charges from OpenAI and potential data leakage if the keys provide access to fine-tuned models containing proprietary company data.
Recommended Action
Ask your DevOps lead: Are we scanning our public and private repositories for hardcoded API keys, and have we rotated our OpenAI secrets recently?
High Severity
Hacktivists, State Actors, Cybercriminals Target Global Defense Industry
Google warns that threat actors from Russia, China, North Korea, and Iran are actively targeting the global defense industrial base. The campaign involves a mix of espionage and potential disruptive capabilities.
Business Impact
Defense contractors face severe risks of intellectual property theft regarding sensitive military technologies, which could lead to contract termination, regulatory penalties, and loss of competitive advantage.
Recommended Action
Ask your Threat Intel team: Are we monitoring for the specific TTPs associated with these nation-state groups, particularly regarding our engineering environments?
How to Prevent Vishing Attacks Targeting Okta and other IDPs
Threat groups like ShinyHunters are operationalizing voice phishing (vishing) to bypass Multi-Factor Authentication (MFA) on identity platforms like Okta. Attackers call help desks or users directly to trick them into approving login requests.
Business Impact
If an attacker bypasses MFA, they gain legitimate-looking access to corporate systems, rendering password policies useless and allowing for undetected data exfiltration or ransomware deployment.
Recommended Action
Ask your CISO: Have we implemented FIDO2/WebAuthn hardware keys or phishing-resistant MFA for all privileged accounts to neutralize vishing attempts?
Once-hobbled Lumma Stealer is back with lures that are hard to resist
The Lumma information stealer malware has resurfaced with new distribution methods after a previous law enforcement disruption. It targets Windows computers to steal credentials, crypto wallets, and browser data.
Business Impact
Widespread infection could lead to mass credential theft, enabling initial access brokers to sell entry into the corporate network to ransomware gangs.
Recommended Action
Ask your Endpoint Security team: Does our EDR solution have updated signatures and behavioral rules to detect the latest Lumma Stealer variants?
Microsoft to Enable ‘Windows Baseline Security’ With New Runtime Integrity Safeguards
Microsoft is rolling out new default runtime safeguards for Windows to ensure only properly signed software runs. This moves security from static checking to continuous runtime verification.
Business Impact
While improving security, this could impact legacy or custom in-house applications that are not properly signed, potentially causing operational disruptions if not tested.
Recommended Action
Ask your IT Operations: Have we audited our internal software catalog to ensure all critical business applications are digitally signed and compatible with these new enforcement modes?
OpenClaw Open Source AI Agent Application Attack Surface and Security Risk System Analysis
Digital asset theft hit $3.4B in 2025 — Lazarus Group accounts for 75% of attacks
Other Noteworthy
OpenClaw Open Source AI Agent Application Attack Surface and Security Risk System Analysis
Digital asset theft hit $3.4B in 2025 — Lazarus Group accounts for 75% of attacks
Executive Briefing
Despite AI promises, cybersecurity teams still spend 44% of their time on manual tasks. Executives should focus AI investments on practical automation to reduce burnout and alert fatigue.
CISOs must adapt to AI-driven threats by enhancing visibility and aligning security strategies with board-level business objectives. The focus is shifting from pure defense to adaptive risk management.
Vendor Spotlight
Specialization: Apple Enterprise Management & Endpoint Security
Why Jamf Today: The provided threat list highlights a critical, actively exploited zero-day flaw affecting Apple devices (CVE-2026-20700). Jamf is specifically relevant as the market leader in Apple Enterprise Management and security, enabling organizations to rapidly enforce OS updates to patch this vulnerability and monitor for device compromise.
Key Capability: Automated patch enforcement and behavioral threat detection for macOS and iOS fleets.
Recommended Actions: 1. Navigate to Jamf Pro Console → Computers → Smart Computer Groups → New 2. Navigate to Jamf Pro Console → Computers → Smart Computer Groups → [Vulnerable Group Name] → View → Action → Send Remote Commands 3. Navigate to Jamf Protect Console → Analytics → Threat Prevention → Plans → [Active Plan]
Verification Steps: - Review Smart Group Membership in Jamf Pro Dashboard - Monitor Jamf Protect Alerts Dashboard for 'Exploit Prevention' tags
Detection & Response
⚠️ Disclaimer: Test all detection logic in non-production environments before deployment.
1. Vendor Platform Configuration - Jamf
2. YARA Rule for Apple WebKit Zero-Day (CVE-2026-20700)
3. SIEM Query — Ivanti/Ransomware Activity
4. PowerShell Script — Check for Notepad++ Signature
This rundown should provide a solid overview of the current threat landscape. Thank you to all our cyberheroes for your diligence and hard work. Stay vigilant!