CyberSecurity Knuggets

Feb 21, 2026

  1. ** Risky Bulletin – RPKI infrastructure sits on shaky grounds**
  2. Researchers reveal serious vulnerabilities in the RPKI infrastructure that secures internet routing.
  3. 31 out of 64 Publishing Point (PP) servers are vulnerable to DNS spoofing due to lack of DNSSEC.
  4. Potential attacks could impact 65%-83% of all Autonomous Systems (ASes) causing cascading failures.
  5. Recommendations include implementation of DNSSEC for PP domain names, ROA coverage for PPs and DNS servers, and avoiding use of CDNs for hosting PP servers.
  6. Other news: breach at French Ministry of Economy exposing 1.2 million bank accounts, concerns over tech platform policies in the UK, increase in malware infections linked to ClickFix, and various cybersecurity incidents worldwide.

  7. ** Hacker Newsletter #783**

  8. Highlights from Hacker News including topics on AI, cybersecurity, development, and privacy.
  9. Featured content includes AI’s impact on productivity, problems with AI-generated passwords, use of generative AI in malware persistence.
  10. New and interesting projects highlighted such as Webflow’s AI website builder, Micasa home tracking from terminal, and Monosketch.
  11. Discussions around surveillance by major companies (Amazon’s Ring, Google Nest).
  12. Various coding, data, design, startup, and book recommendations.
  13. Emphasis on the importance of using protocols over services for security.

  14. ** African cops bust 651 suspected cyber scammers across 16 countries**

  15. Interpol-led operation arrested 651 suspects involved in investment fraud, mobile scams, and fake loan apps across 16 African countries.
  16. Over $4.3 million recovered; over 2,300 devices and 1,442 malicious websites seized.
  17. Arrests include Nigerian cybercrime gang members and operators of fraudulent social media accounts.
  18. Additional news: West Virginia sues Apple over child sexual abuse material on iCloud, Ukrainian sentenced for North Korean IT worker scam, Mississippi University Medical Center ransomware attack causing clinic closures.
  19. Predator spyware now capable of hiding iOS recording indicators, Honeywell CCTV vulnerability allowing account hijacking.
  20. Notable incidents include Cline AI coding tool hijacked to deploy malware and Microsoft working on improved digital content authenticity standards.
  21. FBI reports over 700 ATM jackpotting attacks in 2025 causing $20 million loss.
  22. Google cracked down on 1.75 million policy-violating apps in 2025 with increased use of AI for detection.
  23. New Android malware PromptSpy uses Google Gemini AI to persist on devices.

  24. ** Chip Testing Giant Hit by Ransomware**

  25. Semiconductor testing company Advantest suffers potential ransomware attack with part of internal systems accessed illegally.
  26. Incident under investigation for extent of impact including customer and employee data.
  27. Washington Hotel in Japan hit by ransomware exposing internal business data, servers disconnected to prevent spread.
  28. Other headlines: NIST achieves quantum breakthrough producing single photons on chip, FBI reports sharp rise in ATM jackpotting attacks, Figure blockchain company suffers data breach affecting nearly 1 million users, German rail company Deutsche Bahn suffers DDoS attacks.
  29. Security advisories include exploitation of vulnerabilities in products from BeyondTrust, OpenClaw-related security issues, and new Android malware using generative AI identified.
  30. Discussions on AI-assisted software development risks and hidden info security failures.

  31. ** Dutch intelligence warns of escalating Russian cyber operations**

  32. Dutch intelligence warns Russia is escalating hybrid cyber operations including cyberattacks, sabotage, and covert influence campaigns in preparation for prolonged confrontation with the West.
  33. Russia expanding and reforming armed forces and conducting operations testing Western resolve while avoiding full-scale war.
  34. Cyberattack on University of Mississippi Medical Center disrupts electronic medical records system causing statewide clinic closures.
  35. ESET reports “PromptSpy,” the first Android malware integrating generative AI for UI navigation to evade termination.
  36. Nigerian hacker sentenced to eight years after phishing tax firms and fraudulently claiming $8+ million refunds.
  37. Supplemented with sponsored content about AI security and malware reverse engineering.
  38. Additional selected reading on RAT malware posing as remote monitoring tools, PayPal data breach, and FBI warnings on ATM jackpotting.

Stay Well!

summy
summy