Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (17 February 2026)
Published: Loading…
At a Glance
- Google released Chrome 145 updates fixing CVE-2026-2441, a CSS use-after-free vulnerability exploited to execute sandboxed code via malicious webpages remotely.
- ClickFix campaigns now abuse nslookup DNS queries to retrieve PowerShell payloads and deliver ModeloRAT through social-engineering instructions to targeted users.
- Dutch telecom Odido disclosed a data breach affecting more than six million customers, exposing subscriber information across its services nationwide.
- LockBit 5.0 ransomware introduces coordinated attacks targeting Windows, Linux, and VMware ESXi systems using dedicated enterprise-focused builds simultaneously across environments.
- Malicious npm packages mimicking json-bigint installed Express backdoors enabling remote SQL execution, file access, and manipulation of gambling transactions silently.
- Five malicious Chrome extensions hijacked more than 500,000 VKontakte accounts, altering settings and maintaining persistent unauthorized platform access globally reportedly.
Summary
Exploitation of browser platforms intensified with the CVE-2026-2441 Chrome zero-day enabling sandboxed code execution through crafted webpages. Separately, malicious Chrome extensions hijacked over 500,000 VKontakte accounts by modifying settings and maintaining persistent unauthorised access.
Malware delivery methods expanded as ClickFix campaigns used nslookup DNS queries to retrieve payloads delivering ModeloRAT through social-engineering instructions. Concurrently, malicious npm packages impersonating json-bigint deployed Express backdoors capable of remote SQL execution, file access, and manipulation of gambling transaction records.
Large-scale data exposures affected telecommunications and travel sectors, with Odido reporting a breach impacting more than six million customers. Stolen traveller information from Eurail breaches also surfaced for sale on underground markets, while Canada Goose customer transaction datasets were leaked online.
Ransomware operations continued targeting enterprise infrastructure as LockBit 5.0 introduced coordinated cross-platform attacks against Windows, Linux, and VMware ESXi systems. A separate incident saw Washington Hotel disclose a ransomware infection that compromised internal business servers and operational data.
Application security weaknesses exposed messaging and development platforms, including a Gogs IDOR flaw allowing cross-repository comment deletion through manipulated identifiers. The Nanobot WhatsApp bridge vulnerability also enabled unauthenticated session hijacking, allowing attackers to intercept messages and impersonate users over exposed WebSocket services.
Highlights of the Day
Hackers leak 600,000 Canada Goose customer records
ShinyHunters claims to have published a 1.67 GB dataset containing more than 600,000 Canada Goose customer records, including names, contact details, order histories and partial payment card information. Canada Goose said it has found no evidence of a breach of its own systems and is reviewing the data, adding that no unmasked financial data appears to be involved. The group alleges the records originated from a third-party payment processor, though this has not been independently verified.
Google fixes exploited Chrome zero-day in CSS engine
Google has released Chrome 145.0.7632.75/76 for Windows and macOS, and 144.0.7559.75 for Linux, addressing a high-severity use-after-free vulnerability in the browser’s CSS component. Tracked as CVE-2026-2441, the flaw could allow a remote attacker to execute arbitrary code within Chrome’s sandbox via a crafted HTML page. Google confirmed that an exploit for the vulnerability exists in the wild and has restricted detailed bug information until most users are updated.
Gogs flaw allowed cross-repository comment deletion
Tenable Research disclosed an insecure direct object reference (IDOR) vulnerability in the Gogs Git service that allowed repository administrators to delete comments from unrelated repositories by manipulating comment IDs. The issue stemmed from insufficient authorisation checks in the comment deletion endpoint, which failed to verify repository ownership. The flaw was fixed in Gogs version 0.14.1 following coordinated disclosure.
Malicious npm packages backdoor gambling platforms, alter payment logic
Security researchers identified several malicious npm packages impersonating the popular json-bigint library that deploy targeted backdoors when executed in specific environments. The malware injects middleware capable of executing remote commands, accessing databases and files, and dynamically modifying payment or game transaction records to manipulate gambling outcomes while preserving internal accounting consistency. The packages appear designed for highly targeted supply-chain attacks rather than broad compromise.
Study finds password recovery attacks in major password managers
Academic researchers identified 27 potential password recovery and vault-compromise attack scenarios affecting several cloud-based password managers, including Bitwarden, LastPass, Dashlane, and 1Password, under a malicious-server threat model. The weaknesses stem from issues such as key escrow recovery mechanisms, item-level encryption design, sharing features, and legacy cryptography compatibility, which in some cases could enable password recovery or vault integrity violations. Vendors said mitigations are underway or already implemented, and there is no evidence the issues have been exploited in real-world attacks.
Daily Coverage