Heroes, your curated look at the current cybersecurity landscape for Feb 18, 2026.
Critical Threats
China-linked APT Weaponizes Dell RecoverPoint Zero-Day
A suspected Chinese state-sponsored group has been exploiting a zero-day vulnerability in Dell RecoverPoint since mid-2024 to deploy custom malware families. This campaign targets storage protection software critical for disaster recovery, allowing attackers to persist deep within enterprise infrastructure.
Business Impact
If exploited, attackers gain long-term persistence in your backup infrastructure—expect potential data exfiltration, ransom leverage over backups, and significant remediation costs involving hardware wipes.
Recommended Action
Ask your IT team: "Have we applied the latest Dell RecoverPoint patches to address CVE-2026-22769, and have we scanned our backup appliances for the 'SLAYSTYLE' or 'BRICKSTORM' malware indicators?"
Critical Flaws in VS Code Extensions with 125M Installs
Researchers identified critical vulnerabilities in four massive Visual Studio Code extensions that allow attackers to steal local files and execute remote code on developer machines. These extensions are ubiquitous in development environments, turning trusted tools into entry points.
Business Impact
If exploited, attackers could steal your proprietary source code, API keys, and intellectual property directly from developer laptops—expect loss of competitive advantage and potential downstream supply chain attacks on your customers.
Recommended Action
Ask your AppSec team: "Have we audited our developers' VS Code environments for the four vulnerable extensions and enforced an update or removal policy?"
The Phone is Listening: Critical Grandstream VoIP Vulnerability
A critical unauthenticated stack buffer overflow in Grandstream GXP1600 VoIP phones allows attackers to turn devices into listening posts. This "Cold War-style" vulnerability permits remote eavesdropping without user interaction.
Business Impact
If exploited, sensitive boardroom conversations and trade secrets discussed over the phone could be recorded by competitors or nation-states—expect severe reputational damage and loss of confidential strategy.
Recommended Action
Ask your Network team: "Do we use Grandstream GXP1600 phones, and if so, are they isolated from the public internet and patched against CVE-2026-2329 immediately?"
CISA Adds Four Flaws to Known Exploited Vulnerabilities Catalog
CISA has updated its KEV catalog with four new vulnerabilities, including a high-severity use-after-free flaw, confirming active exploitation in the wild. Federal agencies and critical infrastructure are mandated to patch these immediately.
Business Impact
If exploited, you face known attack vectors that are currently being automated by threat actors—expect regulatory scrutiny if a breach occurs via a known exploited vulnerability.
Recommended Action
Ask your Vulnerability Management team: "Have we prioritized the remediation of CVE-2026-2441 and the other three new CISA KEV additions in our next patch cycle?"
Chrome Zero-Day Exploited in Operation ForumTroll
A sophisticated state-sponsored campaign dubbed "Operation ForumTroll" leveraged a Google Chrome zero-day vulnerability to target specific organizations. The attack demonstrates high capability and intent to compromise browser security.
Business Impact
If exploited, employees browsing legitimate sites could be compromised—expect potential entry points for ransomware or data theft via the browser.
Recommended Action
Ask your IT team: "Is our browser fleet managed, and have we enforced the update that patches CVE-2025-2783 across all endpoints?"
High Severity
Job Scam Harvests Google Logins via Fake Forms
Phishers are utilizing fake Google Forms hosted on lookalike domains to target job seekers and harvest credentials. This social engineering tactic exploits the trust users place in the Google brand.
Business Impact
If exploited, employee credentials could be harvested—expect unauthorized access to corporate email and cloud resources.
Recommended Action
Ask your Security Awareness team: "Have we alerted employees about job application scams using fake Google Forms and reinforced URL verification training?"
AI Finds Twelve New Vulnerabilities in OpenSSL
New research demonstrates the efficacy of AI in security auditing, uncovering 12 previously unknown vulnerabilities in the OpenSSL library. This highlights both the risk of undiscovered flaws in core infrastructure and the potential of AI-aided defense.
Scammers Use Fake "Gemini" AI to Sell Crypto
Fraudsters are deploying a fake AI chatbot posing as Google's Gemini to promote a non-existent "Google Coin." The scam promises unrealistic returns to lure victims into financial loss.
Palo Alto Networks to Acquire Koi for $400M
Palo Alto Networks is set to acquire endpoint security firm Koi to enhance its product portfolio. This consolidation indicates continued aggressive expansion by major platform vendors.
Cyber Startups to Shine at RSAC 2026
The Innovation Sandbox at RSAC 2026 will highlight AI-based security solutions, marking the 21st year of the contest. This event often predicts future industry standards and investment trends.
Other Noteworthy
AI Finds Twelve New Vulnerabilities in OpenSSL
New research demonstrates the efficacy of AI in security auditing, uncovering 12 previously unknown vulnerabilities in the OpenSSL library. This highlights both the risk of undiscovered flaws in core infrastructure and the potential of AI-aided defense.
Scammers Use Fake "Gemini" AI to Sell Crypto
Fraudsters are deploying a fake AI chatbot posing as Google's Gemini to promote a non-existent "Google Coin." The scam promises unrealistic returns to lure victims into financial loss.
Palo Alto Networks to Acquire Koi for $400M
Palo Alto Networks is set to acquire endpoint security firm Koi to enhance its product portfolio. This consolidation indicates continued aggressive expansion by major platform vendors.
Cyber Startups to Shine at RSAC 2026
The Innovation Sandbox at RSAC 2026 will highlight AI-based security solutions, marking the 21st year of the contest. This event often predicts future industry standards and investment trends.
Executive Briefing
Microsoft's latest research argues that traditional SOC models based on network logs and manual triage are failing under tool sprawl. The report suggests that unifying operations is no longer optional but a financial necessity to keep pace with threat actors.
Vendor Spotlight
Specialization: Network Detection and Response (NDR)
Why ExtraHop Today: ExtraHop's Network Detection and Response (NDR) platform is critical for identifying the network anomalies associated with the China-linked APT exploiting Dell RecoverPoint, specifically by detecting lateral movement and command-and-control traffic. Furthermore, their ability to analyze wire data allows for the detection of exploitation attempts against infrastructure protocols, such as those described in the modern VoIP vulnerability.
Key Capability: Real-time decryption and analysis of network traffic to uncover hidden threats and zero-day exploits.
Recommended Actions: 1. Navigate to Reveal(x) Web UI → Assets → Device Groups → Create Device Group 2. Navigate to Reveal(x) Web UI → Detections → Filter by Category: 'Command & Control' and 'Lateral Movement' 3. Navigate to Reveal(x) Web UI → Records → Query → Record Type: 'SIP'
Verification Steps: - Select the 'Critical Infrastructure' Device Group and view the 'Activity Map' - Review 'Detections' timeline for the past 24 hours filtered by the specific Device Group
Detection & Response
⚠️ Disclaimer: Test all detection logic in non-production environments before deployment.
1. Vendor Platform Configuration - ExtraHop
2. YARA Rule for Dell RecoverPoint APT (UNC6201)
3. SIEM Query — Ivanti EPMM Exploitation Attempt
4. PowerShell Script — Check for Grandstream Vulnerability Exposure
This rundown should provide a solid overview of the current threat landscape. Thank you to all our cyberheroes for your diligence and hard work. Stay vigilant!