Wednesday, February 18, 2026

MikeGPT CyberSecurity

“Playbook for the Secure Enterprise”

MikeGPT Daily Threat Rundown

Heroes, your curated look at the current cybersecurity landscape for Feb 18, 2026.

Critical Threats

China-linked APT Weaponizes Dell RecoverPoint Zero-Day

    A suspected Chinese state-sponsored group has been exploiting a zero-day vulnerability in Dell RecoverPoint since mid-2024 to deploy custom malware families. This campaign targets storage protection software critical for disaster recovery, allowing attackers to persist deep within enterprise infrastructure.

    Business Impact

    If exploited, attackers gain long-term persistence in your backup infrastructure—expect potential data exfiltration, ransom leverage over backups, and significant remediation costs involving hardware wipes.

    Recommended Action

    Ask your IT team: "Have we applied the latest Dell RecoverPoint patches to address CVE-2026-22769, and have we scanned our backup appliances for the 'SLAYSTYLE' or 'BRICKSTORM' malware indicators?"

Researchers identified critical vulnerabilities in four massive Visual Studio Code extensions that allow attackers to steal local files and execute remote code on developer machines. These extensions are ubiquitous in development environments, turning trusted tools into entry points.

Business Impact

If exploited, attackers could steal your proprietary source code, API keys, and intellectual property directly from developer laptops—expect loss of competitive advantage and potential downstream supply chain attacks on your customers.

Recommended Action

Ask your AppSec team: "Have we audited our developers' VS Code environments for the four vulnerable extensions and enforced an update or removal policy?"

General Enterprise The Hacker News ↗
The Phone is Listening: Critical Grandstream VoIP Vulnerability

    A critical unauthenticated stack buffer overflow in Grandstream GXP1600 VoIP phones allows attackers to turn devices into listening posts. This "Cold War-style" vulnerability permits remote eavesdropping without user interaction.

    Business Impact

    If exploited, sensitive boardroom conversations and trade secrets discussed over the phone could be recorded by competitors or nation-states—expect severe reputational damage and loss of confidential strategy.

    Recommended Action

    Ask your Network team: "Do we use Grandstream GXP1600 phones, and if so, are they isolated from the public internet and patched against CVE-2026-2329 immediately?"

    CVE-2026-2329 General Enterprise Rapid7 ↗

CISA has updated its KEV catalog with four new vulnerabilities, including a high-severity use-after-free flaw, confirming active exploitation in the wild. Federal agencies and critical infrastructure are mandated to patch these immediately.

Business Impact

If exploited, you face known attack vectors that are currently being automated by threat actors—expect regulatory scrutiny if a breach occurs via a known exploited vulnerability.

Recommended Action

Ask your Vulnerability Management team: "Have we prioritized the remediation of CVE-2026-2441 and the other three new CISA KEV additions in our next patch cycle?"

CVE-2026-2441 General Enterprise The Hacker News ↗
Chrome Zero-Day Exploited in Operation ForumTroll

    A sophisticated state-sponsored campaign dubbed "Operation ForumTroll" leveraged a Google Chrome zero-day vulnerability to target specific organizations. The attack demonstrates high capability and intent to compromise browser security.

    Business Impact

    If exploited, employees browsing legitimate sites could be compromised—expect potential entry points for ransomware or data theft via the browser.

    Recommended Action

    Ask your IT team: "Is our browser fleet managed, and have we enforced the update that patches CVE-2025-2783 across all endpoints?"

    CVE-2025-2783 General Enterprise NSFOCUS ↗

High Severity

Job Scam Harvests Google Logins via Fake Forms

    Phishers are utilizing fake Google Forms hosted on lookalike domains to target job seekers and harvest credentials. This social engineering tactic exploits the trust users place in the Google brand.

    Business Impact

    If exploited, employee credentials could be harvested—expect unauthorized access to corporate email and cloud resources.

    Recommended Action

    Ask your Security Awareness team: "Have we alerted employees about job application scams using fake Google Forms and reinforced URL verification training?"

    General Enterprise Malwarebytes ↗
AI Finds Twelve New Vulnerabilities in OpenSSL

    New research demonstrates the efficacy of AI in security auditing, uncovering 12 previously unknown vulnerabilities in the OpenSSL library. This highlights both the risk of undiscovered flaws in core infrastructure and the potential of AI-aided defense.

    General Enterprise Schneier on Security ↗

Fraudsters are deploying a fake AI chatbot posing as Google's Gemini to promote a non-existent "Google Coin." The scam promises unrealistic returns to lure victims into financial loss.

General Enterprise Malwarebytes ↗

Palo Alto Networks is set to acquire endpoint security firm Koi to enhance its product portfolio. This consolidation indicates continued aggressive expansion by major platform vendors.

The Innovation Sandbox at RSAC 2026 will highlight AI-based security solutions, marking the 21st year of the contest. This event often predicts future industry standards and investment trends.

Other Noteworthy

AI Finds Twelve New Vulnerabilities in OpenSSL

    New research demonstrates the efficacy of AI in security auditing, uncovering 12 previously unknown vulnerabilities in the OpenSSL library. This highlights both the risk of undiscovered flaws in core infrastructure and the potential of AI-aided defense.

    General Enterprise Schneier on Security ↗

Fraudsters are deploying a fake AI chatbot posing as Google's Gemini to promote a non-existent "Google Coin." The scam promises unrealistic returns to lure victims into financial loss.

General Enterprise Malwarebytes ↗

Palo Alto Networks is set to acquire endpoint security firm Koi to enhance its product portfolio. This consolidation indicates continued aggressive expansion by major platform vendors.

The Innovation Sandbox at RSAC 2026 will highlight AI-based security solutions, marking the 21st year of the contest. This event often predicts future industry standards and investment trends.

Executive Briefing

Unify Now or Pay Later: The Cost of Fragmented SOCs

Microsoft's latest research argues that traditional SOC models based on network logs and manual triage are failing under tool sprawl. The report suggests that unifying operations is no longer optional but a financial necessity to keep pace with threat actors.

Microsoft Security Blog · 5:00 PM ·

Vendor Spotlight

ExtraHop

Specialization: Network Detection and Response (NDR)

Why ExtraHop Today: ExtraHop's Network Detection and Response (NDR) platform is critical for identifying the network anomalies associated with the China-linked APT exploiting Dell RecoverPoint, specifically by detecting lateral movement and command-and-control traffic. Furthermore, their ability to analyze wire data allows for the detection of exploitation attempts against infrastructure protocols, such as those described in the modern VoIP vulnerability.

Key Capability: Real-time decryption and analysis of network traffic to uncover hidden threats and zero-day exploits.

Recommended Actions: 1. Navigate to Reveal(x) Web UI → Assets → Device Groups → Create Device Group 2. Navigate to Reveal(x) Web UI → Detections → Filter by Category: 'Command & Control' and 'Lateral Movement' 3. Navigate to Reveal(x) Web UI → Records → Query → Record Type: 'SIP'

Verification Steps: - Select the 'Critical Infrastructure' Device Group and view the 'Activity Map' - Review 'Detections' timeline for the past 24 hours filtered by the specific Device Group

Learn More About ExtraHop ↗

Detection & Response

Detection & Response Kit (4 items)

⚠️ Disclaimer: Test all detection logic in non-production environments before deployment.

1. Vendor Platform Configuration - ExtraHop

# Actionable Guidance for ExtraHop # Generated: 2026-02-18 15:11:19 # Step 1: Navigate to Reveal(x) Web UI → Assets → Device Groups → Create Device Group # Purpose: Isolate Dell RecoverPoint appliances and VoIP infrastructure into a specific 'Critical Infrastructure' watch list to enable focused anomaly detection. # Expected: A dedicated device group containing the target assets, allowing for granular alert tuning and specific 'Risk Score' monitoring separate from the general network. # Step 2: Navigate to Reveal(x) Web UI → Detections → Filter by Category: 'Command & Control' and 'Lateral Movement' # Purpose: Identify active APT behaviors associated with the Dell RecoverPoint exploit, specifically looking for 'Suspicious SMB/RPC Activity' or 'DNS Tunneling' originating from the newly created device group. # Expected: A filtered list of high-fidelity detections highlighting any instances where RecoverPoint appliances are initiating unexpected connections to internal servers (Lateral Movement) or external IPs (C2). # Step 3: Navigate to Reveal(x) Web UI → Records → Query → Record Type: 'SIP' # Purpose: Investigate the VoIP vulnerability aspect by analyzing wire data for malformed SIP headers or unusual User-Agent strings indicative of exploitation attempts. # Expected: A transactional list of SIP sessions. Look for '4xx' or '5xx' error spikes or SIP OPTIONS requests from unauthorized external IP addresses targeting the VoIP infrastructure. # Verification Steps: # - Select the 'Critical Infrastructure' Device Group and view the 'Activity Map' # Expected: Visual confirmation of traffic flows. Success is defined by a clean map showing only expected management ports; any unexpected East-West traffic (e.g., SMB to a Domain Controller) should be immediately visible as a red/orange line. # - Review 'Detections' timeline for the past 24 hours filtered by the specific Device Group # Expected: Confirmation that the detection engine is profiling the devices. If no active exploit exists, the 'Risk Score' should remain stable. If an exploit is attempted, a specific detection card (e.g., 'Exploit Attempt') should appear.

2. YARA Rule for Dell RecoverPoint APT (UNC6201)

rule APT_Dell_RecoverPoint_UNC6201 { meta: description = "Detects malware artifacts associated with UNC6201/Ghost targeting Dell RecoverPoint (CVE-2026-22769)" author = "Threat Rundown" date = "2026-02-18" reference = "https://securityaffairs.com/?p=188176" severity = "critical" tlp = "white" strings: $s1 = "SLAYSTYLE" ascii wide $s2 = "BRICKSTORM" ascii wide $s3 = "GRIMBOLT" ascii wide $s4 = "UNC6201" ascii wide $h1 = { 4D 5A 90 00 03 00 00 00 04 00 00 00 FF FF 00 00 } condition: uint16(0) == 0x5A4D and (any of ($s*) or $h1) }

3. SIEM Query — Ivanti EPMM Exploitation Attempt

index=security sourcetype="web_proxy" OR sourcetype="iis" uri_path="*/mifs/*" OR uri_path="*/mobileiron/*" | eval risk_score=case( status==200 AND method=="POST", 100, status==403, 50, 1==1, 0) | where risk_score >= 50 | table _time, src_ip, dest_ip, uri_path, user_agent, risk_score | sort -_time

4. PowerShell Script — Check for Grandstream Vulnerability Exposure

$computers = "localhost", "SERVER01", "WKSTN01" foreach ($computer in $computers) { if (Test-Connection -ComputerName $computer -Count 1 -Quiet) { # Check for open ports commonly used by Grandstream GXP1600 (SIP/HTTP) $ports = 5060, 80 foreach ($port in $ports) { $conn = Test-NetConnection -ComputerName $computer -Port $port -WarningAction SilentlyContinue if ($conn.TcpTestSucceeded) { Write-Host "WARNING: $computer has Port $port open - Verify if Grandstream device (CVE-2026-2329)" -ForegroundColor Red } } } }

This rundown should provide a solid overview of the current threat landscape. Thank you to all our cyberheroes for your diligence and hard work. Stay vigilant!