CyberSecurity Knuggets

Feb 13, 2026

Here are summaries of the contents of the first 5 emails based on the provided text:

Subject: Srsly Risky Biz: Microsoft’s Forgoes Its Secure Future

– Microsoft’s brief commitment to prioritize security seems to have ended with leadership changes.

– Charlie Bell, formerly EVP of Security at Microsoft, replaced by Hayete Gallot, signals a shift from making secure products to selling security products.

– Microsoft’s history shows security was only prioritized under government pressure after breaches by Chinese and Russian state hackers.

– Bell had limited success due to internal resistance; now focus appears to be on sales targets rather than genuine security improvements.

– Additional topics include leaked Chinese documents revealing preparation for cyber disruption of power grids and transportation networks, and US cyber operations disrupting Iranian air defenses.

– Some positive news: FTC warnings to data brokers, disruptions caused by Starlink in Russia, and ransomware victims rarely paying ransoms.

Subject: US drops China Telecom, TP-Link router, and other data security bans before trade talks

– Trump administration shelving key tech security measures targeting China before a planned high-level trade meeting.

– Measures paused include bans on China Telecom’s US operations, sales restrictions on TP-Link routers and Chinese telecom businesses.

– Crypto-funded human trafficking transactions soared in 2025, mainly involving Chinese-speaking criminal groups using Telegram.

– US prosecutors confirm a former defense contractor exec stole and sold hacking tools to Russian clients causing harm to US intelligence.

– State-backed hackers from multiple countries (China, Iran, North Korea, Russia) abused Google’s Gemini AI for various stages of cyberattacks.

– Apple fixed a zero-day exploited in sophisticated attacks on Apple OS.

– Several major data breaches and cyberattacks reported globally including Dutch telecom provider data breach.

– Increasing weaponization of n-day exploits shortening patch timeframes.

– Israeli cybersecurity firm Check Point acquires AI security startups.

Subject: Just Launched: New Data from 1,800+ Global Security Pros

– Tines published its “Voice of Security 2026” report surveying over 1,800 security professionals worldwide.

– Key findings indicate AI adoption is widespread (99% SOCs use AI), but workloads and burnout remain high.

– AI literacy and prompt engineering are top skills needed.

– 44% of security work is still manual, and 81% of teams reported increased workloads in the past year.

– The report provides insights into why AI alone hasn’t reduced workload or burnout and what is needed to modernize security operations.

Subject: Google warns of nation-state abuse of AI tools | The CyberWire 2.12.26s

– Google’s Threat Intelligence Group reports state-sponsored actors are abusing AI, especially Gemini, to enhance all attack stages such as reconnaissance, phishing, and data exfiltration.

– Malicious Chrome extensions impersonating AI assistants to steal credentials and information were discovered; over 300,000 users installed them.

– ApolloMD healthcare provider reported a cyberattack in May 2025 exposing sensitive data of 626,000 individuals.

– The Qilin ransomware group linked to the ApolloMD breach.

– Additional coverage includes cybersecurity events, trends, threat investigations, and sponsored messages promoting security solutions and conferences.

Subject: Apple Patches iOS Zero-Day Exploited in ‘Extremely Sophisticated Attack’s

– Apple patched a zero-day vulnerability (CVE-2026-20700) exploited in sophisticated attacks targeting Apple operating systems including iOS, macOS, and others.

– Microsoft to release “Windows Baseline Security” with new integrity safeguards.

– Google warns of attacks targeting the defense industry.

– ApolloMD breach impacting 626,000 individuals detailed.

– Funding announcements, new security policies, and emergent vulnerabilities are covered.

– Expert insights discuss securing AI-assisted software development, detecting hidden security failures, and attacker tradecraft evolving with AI.

– Various security patches, vulnerabilities, and recent threat actor activities documented.

– Upcoming virtual cybersecurity events and additional industry news included.

If you need detailed extracts or particular sections summarized further, please let me know!

Stay Well!

summy
summy