CyberSecurity Knuggets
Feb 11, 2026
Email 1:
Subject: Defense companies face a ‘relentless barrage’ of cyberespionage, Google
Summary:
– According to Google’s Threat Intelligence Group, defense companies in the US and EU are targeted heavily by state-sponsored cyber-espionage.
– Attackers are broadening their targets to include industrial suppliers and smaller companies like carmakers and ball bearing manufacturers.
– Russian-linked groups execute phishing attacks by spoofing defense contractors and telecom providers.
– Employees and hiring processes have become major attack surfaces.
– Updates include criminal sentences for crypto-laundering, the scope of the Coupang data breach, Discord’s new age verification requiring facial scans or government IDs, hacktivist data leaks from stalkerware apps, and insights on the Prometei botnet.
– BridgePay suffered a ransomware incident causing a nationwide outage.
– Various global cybersecurity developments, regulatory moves, and government responses are included.
Email 2:
Subject: Safely Adopt GenAI with Zscaler Zero Trust + AIs
Summary:
– Generative AI offers productivity gains but also increases data loss risks and attack surfaces.
– Reported 1.3 million social security numbers leaked to AI apps; 3.2 million data violations in ChatGPT and Microsoft Copilot.
– Zscaler Zero Trust combined with AI technology helps organizations safely adopt public and private AI.
– The solution reduces data loss risk and protects against AI-driven attacks to enhance productivity and compliance.
– Additional resources and reports available to learn more about Zero Trust and AI security.
Email 3:
Subject: New commodity mobile spyware targets iOS and Android devices | The CyberWire 2.10.26s
Summary:
– Researchers at iVerify disclosed “ZeroDayRAT,” a new mobile spyware targeting Android and iOS (up to iPhone 17 Pro).
– Distributed through Trojanized apps on Telegram, it enables total compromise including data collection, location tracking, camera/microphone activation, screen recording, and financial theft.
– The spyware offers sales and support channels, requiring no technical expertise to deploy.
– Threat actors also exploiting vulnerabilities in SolarWinds Web Help Desk actively to deploy malware and maintain persistence.
– A fugitive dual citizen sentenced to 20 years for laundering $73M in cryptocurrency scams involving “pig butchering.”
– Upcoming events and security updates are covered, including the RSAC 2026 conference and calls for urgent patching.
Email 4:
Subject: New ‘ZeroDayRAT’ Spyware Enables Total Compromise of iOS, Android Devices
Summary:
– “ZeroDayRAT” spyware enables full device compromise on iOS and Android, capable of extensive surveillance and control.
– Microsoft patched 6 actively exploited zero-day vulnerabilities.
– Other patches include SAP critical flaws and Adobe vulnerabilities.
– Insights into evolving ransomware tactics focus on stealth rather than loud encryption.
– SecurityWeek shares expert insights about attacker tradecraft leveraging AI.
– Event announcements, cybersecurity M&A updates, and alerts on supply chain security and discontinued device replacements featured.
Stay Well!
