CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (23 February 2026)

Published: Loading…

At a Glance

  • A Russian-speaking threat actor used generative AI services to breach over 600 internet-exposed FortiGate devices across 55 countries in five weeks.
  • CISA added Roundcube flaws CVE-2025-49113 and CVE-2025-68461 to its KEV catalogue following evidence of active remote code execution and XSS exploitation.
  • CVE-2026-2329 in Grandstream GXP1600 VoIP phones enables unauthenticated remote code execution with root privileges via a web API buffer overflow.
  • An attacker accessed France’s national bank account database and exfiltrated 1.2 million records from the government system.
  • Predator spyware hooks iOS SpringBoard APIs to suppress camera and microphone recording indicators while covertly capturing sensor activity.

Summary

Large-scale intrusion activity targeted perimeter infrastructure as more than 600 FortiGate devices across 55 countries were breached using AI-assisted credential abuse. Separately, an attacker accessed France’s national bank account database and exfiltrated 1.2 million records from the government system.

Exploitation of internet-facing software continued with Roundcube vulnerabilities CVE-2025-49113 and CVE-2025-68461 added to the KEV catalogue amid active abuse. A critical flaw, CVE-2026-2329, in Grandstream GXP1600 phones allows unauthenticated remote code execution through a web API buffer overflow.

Commercial surveillance capabilities evolved as Predator spyware suppressed iOS camera and microphone indicators by hooking SpringBoard APIs after device compromise. The malware enables covert sensor monitoring while bypassing visible recording alerts within the operating system.

Malware experimentation and data exposure incidents also surfaced, including the short-lived Arkanix Stealer promoted as an AI-assisted information stealer. In the UK, Cornwall Council disclosed personal details of ten complainants, including contact information, in a complaint handling error reported to the Information Commissioner’s Office.

AI-driven tooling entered defensive workflows as Claude Code Security launched in research preview to scan enterprise codebases for vulnerabilities and suggest patches. A new flaw, CVE-2026-25896, disclosed an entity encoding bypass in the fast-xml-parser open-source project.

Highlights of the Day

Cornwall Council Exposes Complainants’ Data in Complaint Handling Error

Cornwall Council is facing a data protection complaint after personal details of ten individuals who filed complaints against a local councillor were disclosed to her. Although four complainants had requested anonymity, their names, along with home addresses, email addresses and phone numbers, were included in the documents sent to the councillor. The incident has been reported to the Information Commissioner’s Office, while the council has yet to clarify how the unredacted information was shared.

CISA Flags Actively Exploited Roundcube Webmail Vulnerabilities

CISA has added two Roundcube webmail flaws to its Known Exploited Vulnerabilities catalogue following evidence of active abuse. The issues include a critical remote code execution bug (CVE-2025-49113) stemming from unsafe deserialisation and a cross-site scripting flaw (CVE-2025-68461) involving SVG content, both of which have been patched. Security researchers reported that exploitation code for the RCE vulnerability emerged shortly after public disclosure, with no attribution currently confirmed.

Critical Flaw Exposes Grandstream GXP1600 Phones to Remote Takeover

Rapid7 has disclosed CVE-2026-2329, a critical unauthenticated stack-based buffer overflow affecting Grandstream GXP1600 series VoIP phones. The flaw in the devices’ web-based API can enable remote code execution with root privileges, impacting all six models that share the same firmware. Grandstream addressed the issue in firmware version 1.0.7.81 following coordinated disclosure.

Source: Rapid7

AI-Assisted Actor Breaches 600 FortiGate Devices Worldwide

Amazon Threat Intelligence reports that a financially motivated, Russian-speaking threat actor used commercial generative AI tools to compromise more than 600 internet-exposed FortiGate devices across 55 countries between January and February 2026. The campaign relied on credential abuse and weak single-factor authentication rather than exploiting new vulnerabilities, enabling access to device configurations, internal networks and, in some cases, Active Directory environments and backup infrastructure. Investigators found extensive AI-generated tooling and attack plans, illustrating how commercial AI services can amplify the scale of relatively unsophisticated operations.

Predator Spyware Silences iOS Camera and Microphone Alerts

Jamf Threat Labs has detailed how the commercial Predator spyware suppresses Apple’s iOS camera and microphone recording indicators after a device is fully compromised. By injecting code into system processes and hooking a private SpringBoard API, the malware exploits Objective-C’s handling of nil messages to block sensor activity updates, preventing the green and orange status dots from appearing. The analysis also outlines additional modules for VoIP recording and camera access, highlighting the spyware’s modular design and post-compromise stealth techniques.

Source: Jamf

Daily Coverage

Developments
Fortigate Mass BreachRoundcube Kev ListingGrandstream RceFrench Bank Data Theft
Vulnerabilities
CVE-2026-25545CVE-2025-49113Webmail (Critical)CVE-2025-68461CVE-2026-25896CVE-2026-2329
Threat Groups
MuddyWater[Also known as: Earth Vetala, Mango Sandstorm] MuddyWater is a cyber espionage group assessed to be a subordinate element within Iran's Ministry of Intelligence and Security (MOIS). Since at least 2017, MuddyWater has targeted a range of government and private organizations across sectors, including telecommunications, local government, defense, and oil and natural gas organizations, in the Middle East, Asia, Africa, Europe, and North America.APT28APT28 is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165. This group has been active since at least 2004. APT28 reportedly compromised the Hillary Clinton campaign, the Democratic National Committee, and the Democratic Congressional Campaign Committee in 2016 in an attempt to interfere with the U. S. presidential election. In 2018, the US indicted five GRU Unit 26165 officers associated with APT28 for cyber operations (including closeaccess operations) conducted between 2014 and 2018 against the World AntiDoping Agency (WADA), the US AntiDoping Agency, a US nuclear facility, the Organization for the Prohibition of Chemical Weapons (OPCW), the Spiez Swiss Chemicals Laboratory, and other organizations. Some of these were conducted with the assistance of GRU Unit 74455, which is also referred to as Sandworm Team.PlayPlay is a ransomware group that has been active since at least 2022 deploying Playcrypt ransomware against the business, government, critical infrastructure, healthcare, and media sectors in North America, South America, and Europe. Play actors employ a doubleextortion model, encrypting systems after exfiltrating data, and are presumed by security researchers to operate as a closed group.