CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (12 February 2026)

Published: Loading…

At a Glance

  • Microsoft patched 59 vulnerabilities on February Patch Tuesday, including six zero-days actively exploited in Windows and Office components.
  • The AgreeTo Outlook add-in was hijacked to deliver a phishing kit, compromising over 4,000 Microsoft account credentials and banking information.
  • The Mispadu banking trojan continues Latin American campaigns using password-protected PDFs and multi-stage scripts to bypass email security gateways.
  • Gunra ransomware RaaS expands affiliate programme with ChaCha20 and RSA-4096 encryption, selective file targeting, and offline execution capabilities.
  • Stealerium malware spreads via multi-lure phishing campaigns with ClickFix and HTA execution chains, exfiltrating credentials, files, and webcam data over Telegram.
  • Ivanti Endpoint Manager fixes high-severity authentication bypass and SQL injection flaws, preventing credential theft and database compromise remotely.

Summary

February Patch Tuesday updates addressed 59 vulnerabilities across Windows and Office, including six actively exploited zero-days. The flaws included security feature bypass, privilege escalation, and denial-of-service vectors.

Modular malware campaigns continued to leverage social engineering and multi-stage delivery chains. Stealerium used ClickFix and HTA loaders to exfiltrate credentials, files, and webcam data, while the RenEngine loader delivered Lumma and ACR stealers via pirated games.

Banking malware activity remained regionally targeted, with Mispadu campaigns focusing on Latin American users via password-protected PDFs and multi-stage script chains that bypassed email security controls.

Ransomware operations expanded through affiliate models, as Gunra RaaS offered ChaCha20 and RSA-4096 encryption, selective file targeting, and offline execution to participants, supporting both Windows and cross-platform attacks.

Enterprise software vulnerabilities were actively mitigated, including high-severity Ivanti Endpoint Manager flaws enabling authentication bypass and SQL injection, which could allow remote credential theft and database compromise.

Abuse of trusted client-side applications persisted, exemplified by the AgreeTo Outlook add-in hijack, which allowed an attacker to deploy a phishing kit and harvest over 4,000 Microsoft accounts and financial credentials.

Industrial control systems received critical patches from vendors like Siemens and Schneider Electric, addressing unauthorised access, code execution, and privilege escalation risks across OT environments.

Highlights of the Day

Microsoft Patches Six Actively Exploited Zero-Days

Microsoft’s February Patch Tuesday addresses six zero-day vulnerabilities that were actively exploited, including three that had been publicly disclosed. The flaws affect components such as Windows Shell, MSHTML, Microsoft Word, Desktop Window Manager and Remote Desktop Services, enabling security feature bypass, elevation of privilege and denial-of-service scenarios. In total, Microsoft fixed 58 vulnerabilities this month, with elevation of privilege issues accounting for the largest share, while only five were rated critical.

Ivanti Patches Endpoint Manager Authentication Bypass, SQL Injection Flaws

Ivanti has released updates addressing more than a dozen vulnerabilities in Endpoint Manager, including a high-severity authentication bypass flaw (CVE-2026-1603) that could expose credential data and a SQL injection issue (CVE-2026-1602) enabling database access. The fixes are included in Endpoint Manager 2024 SU5 and also resolve previously disclosed medium-severity weaknesses. Separately, the company updated guidance for two Endpoint Manager Mobile vulnerabilities that were earlier exploited for unauthorised remote code execution.

Industrial Vendors Patch Multiple High-Severity ICS Vulnerabilities

Siemens, Schneider Electric, Aveva and Phoenix Contact have released security advisories addressing vulnerabilities across a range of industrial control system and operational technology products. The flaws include issues that could enable unauthorised access, denial of service, code execution and privilege escalation, affecting software such as Desigo CC, EcoStruxure components and PI Data Archive. Additional advisories from CISA and other vendors also detailed vulnerabilities in related industrial devices and applications disclosed around the same Patch Tuesday cycle.

Mispadu Banking Trojan Expands Phishing Campaign Delivery Chains

Cofense reports that the Mispadu banking trojan, active since 2019, continues to grow in volume, with weekly phishing campaigns primarily targeting Latin American users but also reaching organisations in Europe. Recent campaigns commonly use password-protected PDFs or HTML applications to initiate multi-stage script chains that deploy the malware while bypassing email security gateways. Updated variants incorporate geofencing, obfuscated scripts and self-propagation through compromised Outlook contacts to expand infections.

Source: Cofense

Gunra Ransomware Expands Affiliate Programme With Advanced Encryption Tools

CloudSEK researchers infiltrated the Gunra ransomware-as-a-service affiliate programme, obtaining access to its management panel and analysing a live ransomware sample. The malware targets Windows and other platforms using a hybrid ChaCha20 and RSA-4096 encryption scheme, selective file targeting, and offline execution designed to avoid network detection. The operation offers configurable ransomware builders and affiliate support, lowering technical barriers for cybercriminal participation.

Source: CloudSEK

SMS Bombing Tools Exploit Hundreds of Authentication APIs

Cyble researchers report a growing ecosystem of SMS and OTP bombing tools that automate large-scale message flooding by exploiting weakly protected authentication APIs across telecommunications, finance, e-commerce and government services. Analysis of multiple repositories identified roughly 843 vulnerable endpoints, with tools using proxy rotation, request randomisation and SSL-bypass techniques to sustain attacks. The ecosystem has evolved into cross-platform applications and commercial web services that simplify execution and expand regional targeting.

Source: Cyble

RenEngine Loader Delivers Lumma and ACR Stealers via Pirated Games

Kaspersky reports a campaign using the RenEngine loader to distribute Lumma and ACR stealers through modified game launchers and pirated software. The loader employs multi-stage injection, memory-resident payloads, and HijackLoader modules to bypass detection and deliver final payloads into system processes. Incidents have been observed worldwide, with the highest impact in Russia, Brazil, Turkey, Spain, and Germany.

Source: Kaspersky

Malicious Outlook Add-In Exposes Over 4,000 Credentials

A previously abandoned Outlook add-in, AgreeTo, was hijacked by an attacker who deployed a phishing kit via the add-in’s manifest. Microsoft’s infrastructure continued serving the compromised URL, allowing the attacker to steal over 4,000 Microsoft account credentials, credit card details, and banking security answers. The case highlights structural risks in Office add-ins, where remote content can be modified without further review, even after initial approval.

Source: Koi

Stealerium Campaign Exploits Multi-Stage Phishing for Data Theft

Researchers have uncovered a large-scale malware campaign delivering Stealerium, a modular .NET infostealer with keylogging, file theft, clipboard hijacking, webcam capture, and Telegram-based exfiltration. The campaign uses evolving social engineering lures, password-protected ZIPs, and user-assisted ClickFix execution chains, but consistently deploys the same Stealerium payload via HTA, PowerShell, and reflective in-memory loaders. This operational model separates flexible front-end delivery from a stable execution core, enabling rapid retargeting while supporting credential theft, high-value file exfiltration, and optional ransomware activation.

Daily Coverage

Developments
Microsoft Zero-DaysAgreetosteal HijackMispadu CampaignsGunra Raas
Vulnerabilities
CVE-2026-20700Macos UnspecifiedCVE-2025-14174Out Of Bounds Memory Access In Angle In Google Chrome On Mac Prior To 143.0.7499.110 Allowed A Remote Attacker To Perform Out Of Bounds Memory Access Via A Crafted Html Page. (Chromium Security Severity: High)CVE-2025-43529CVE-2026-20841Windows Notepad 11.0.0 (High)CVE-2026-0969CVE-2026-1731Remote Support(Rs) & Privileged Remote Access(Pra) (Critical)CVE-2026-24009CVE-2026-1603Endpoint_Manager 2024 (High)CVE-2026-1602Endpoint_Manager 2024 (Medium)CVE-2025-40551Web Help Desk 12.8.8 Hf1 And Below (Critical)
Threat Groups
APT31ZIRCONIUM is a threat group operating out of China, active since at least 2017, that has targeted individuals associated with the 2020 US presidential election and prominent leaders in the international affairs community.Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.SILICONSea Turtle is a Türkiyelinked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. Sea Turtle is notable for targeting registrars managing ccTLDs and complex DNSbased intrusions where the threat actor compromised DNS providers to hijack DNS resolution for ultimate victims, enabling Sea Turtle to spoof log in portals and other applications for credential collection.