Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (23 February 2026)
Published: Loading…
At a Glance
- A Russian-speaking threat actor used generative AI services to breach over 600 internet-exposed FortiGate devices across 55 countries in five weeks.
- CISA added Roundcube flaws CVE-2025-49113 and CVE-2025-68461 to its KEV catalogue following evidence of active remote code execution and XSS exploitation.
- CVE-2026-2329 in Grandstream GXP1600 VoIP phones enables unauthenticated remote code execution with root privileges via a web API buffer overflow.
- An attacker accessed France’s national bank account database and exfiltrated 1.2 million records from the government system.
- Predator spyware hooks iOS SpringBoard APIs to suppress camera and microphone recording indicators while covertly capturing sensor activity.
Summary
Large-scale intrusion activity targeted perimeter infrastructure as more than 600 FortiGate devices across 55 countries were breached using AI-assisted credential abuse. Separately, an attacker accessed France’s national bank account database and exfiltrated 1.2 million records from the government system.
Exploitation of internet-facing software continued with Roundcube vulnerabilities CVE-2025-49113 and CVE-2025-68461 added to the KEV catalogue amid active abuse. A critical flaw, CVE-2026-2329, in Grandstream GXP1600 phones allows unauthenticated remote code execution through a web API buffer overflow.
Commercial surveillance capabilities evolved as Predator spyware suppressed iOS camera and microphone indicators by hooking SpringBoard APIs after device compromise. The malware enables covert sensor monitoring while bypassing visible recording alerts within the operating system.
Malware experimentation and data exposure incidents also surfaced, including the short-lived Arkanix Stealer promoted as an AI-assisted information stealer. In the UK, Cornwall Council disclosed personal details of ten complainants, including contact information, in a complaint handling error reported to the Information Commissioner’s Office.
AI-driven tooling entered defensive workflows as Claude Code Security launched in research preview to scan enterprise codebases for vulnerabilities and suggest patches. A new flaw, CVE-2026-25896, disclosed an entity encoding bypass in the fast-xml-parser open-source project.
Highlights of the Day
Cornwall Council Exposes Complainants’ Data in Complaint Handling Error
Cornwall Council is facing a data protection complaint after personal details of ten individuals who filed complaints against a local councillor were disclosed to her. Although four complainants had requested anonymity, their names, along with home addresses, email addresses and phone numbers, were included in the documents sent to the councillor. The incident has been reported to the Information Commissioner’s Office, while the council has yet to clarify how the unredacted information was shared.
CISA Flags Actively Exploited Roundcube Webmail Vulnerabilities
CISA has added two Roundcube webmail flaws to its Known Exploited Vulnerabilities catalogue following evidence of active abuse. The issues include a critical remote code execution bug (CVE-2025-49113) stemming from unsafe deserialisation and a cross-site scripting flaw (CVE-2025-68461) involving SVG content, both of which have been patched. Security researchers reported that exploitation code for the RCE vulnerability emerged shortly after public disclosure, with no attribution currently confirmed.
Critical Flaw Exposes Grandstream GXP1600 Phones to Remote Takeover
Rapid7 has disclosed CVE-2026-2329, a critical unauthenticated stack-based buffer overflow affecting Grandstream GXP1600 series VoIP phones. The flaw in the devices’ web-based API can enable remote code execution with root privileges, impacting all six models that share the same firmware. Grandstream addressed the issue in firmware version 1.0.7.81 following coordinated disclosure.
AI-Assisted Actor Breaches 600 FortiGate Devices Worldwide
Amazon Threat Intelligence reports that a financially motivated, Russian-speaking threat actor used commercial generative AI tools to compromise more than 600 internet-exposed FortiGate devices across 55 countries between January and February 2026. The campaign relied on credential abuse and weak single-factor authentication rather than exploiting new vulnerabilities, enabling access to device configurations, internal networks and, in some cases, Active Directory environments and backup infrastructure. Investigators found extensive AI-generated tooling and attack plans, illustrating how commercial AI services can amplify the scale of relatively unsophisticated operations.
Predator Spyware Silences iOS Camera and Microphone Alerts
Jamf Threat Labs has detailed how the commercial Predator spyware suppresses Apple’s iOS camera and microphone recording indicators after a device is fully compromised. By injecting code into system processes and hooking a private SpringBoard API, the malware exploits Objective-C’s handling of nil messages to block sensor activity updates, preventing the green and orange status dots from appearing. The analysis also outlines additional modules for VoIP recording and camera access, highlighting the spyware’s modular design and post-compromise stealth techniques.
Daily Coverage