CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (25 February 2026)

Published: Loading…

At a Glance

  • North Korea-linked Lazarus Group deployed Medusa ransomware against US healthcare and Middle East targets, using Comebacker and Blindingcan tools in extortion campaigns.
  • Anthropic reported DeepSeek, Moonshot and MiniMax ran over 16 million Claude queries via 24,000 fraudulent accounts to distill model capabilities.
  • SolarWinds patched four critical Serv-U remote code execution flaws that could allow attackers to execute arbitrary code with root privileges.
  • ShinyHunters claimed breaches at Odido and CarGurus, publishing data from millions of users and prompting breach confirmations from affected companies.
  • A GitHub Codespaces flaw dubbed RoguePilot allowed Copilot prompt injection via Issues to exfiltrate GITHUB_TOKEN and seize repository control.

Summary

North Korea-linked Lazarus Group used Medusa ransomware in extortion attacks targeting US healthcare organisations and entities in the Middle East. The campaigns involved tools including Comebacker and Blindingcan, and Medusa has claimed hundreds of victims as a ransomware-as-a-service operation.

Multiple critical software vulnerabilities prompted remediation activity, including four SolarWinds Serv-U remote code execution flaws enabling root access on unpatched servers. A separate GitHub Codespaces issue, dubbed RoguePilot, enabled Copilot prompt injection through crafted Issues to exfiltrate GITHUB_TOKEN values and take over repositories.

Data breach activity affected major consumer platforms, with ShinyHunters claiming responsibility for intrusions at Odido and CarGurus involving millions of user records. Wynn Resorts also confirmed employee data theft following an extortion threat linked to the same group.

Artificial intelligence systems featured prominently in both offensive and defensive contexts. DeepSeek, Moonshot and MiniMax generated more than 16 million Claude queries through fraudulent accounts to distill model capabilities, while underground forums documented AI tools drafting phishing content and supporting social engineering workflows.

Supply chain and ecosystem abuse extended across developer and advertising platforms. A self-spreading npm campaign dubbed SANDWORM_MODE targeted developers with typosquatted packages, while the 1Campaign cloaking service enabled malicious Google Ads to evade detection and direct victims to phishing infrastructure.

Highlights of the Day

Lazarus Deploys Medusa Ransomware in Healthcare Attacks

North Korean state-backed Lazarus actors are using the Medusa ransomware in campaigns targeting organisations in the US healthcare sector and the Middle East, according to new threat intelligence. Researchers link the activity to tools previously associated with Lazarus, including the Comebacker backdoor and Blindingcan RAT, although the specific sub-group involved remains unclear. Medusa, operated as a ransomware-as-a-service since 2023, has claimed more than 366 victims, with recent attacks including US non-profits and healthcare-related entities.

Source: Symantec

Android SURXRAT Expands With Large AI Model Download

Researchers have identified a new variant of the SURXRAT Android remote access trojan that conditionally downloads a large language model exceeding 23GB from Hugging Face, signalling experimentation with AI-enabled capabilities. Marketed via Telegram under a malware-as-a-service model, SURXRAT offers affiliates extensive surveillance, remote control and ransomware-style screen locking features, and shows code links to the earlier ArsinkRAT family. The malware abuses accessibility permissions and uses Firebase infrastructure for command-and-control, enabling real-time data exfiltration and device manipulation.

Source: Cyble

Copilot Flaw Enables Repository Takeover via Hidden Issue

Orca researchers have disclosed a vulnerability in GitHub Codespaces that allows attackers to exploit GitHub Copilot through passive prompt injection embedded in a malicious issue. When a Codespace is launched from the issue, Copilot can be manipulated into checking out a crafted pull request containing a symbolic link to internal files, enabling the exfiltration of a privileged GITHUB_TOKEN via automatic JSON schema downloads. The exposed token could grant full control over the affected repository, illustrating a new AI-mediated supply chain attack path.

1Campaign Platform Helps Attackers Evade Google Ads Checks

Varonis Threat Labs has uncovered 1Campaign, a cloaking platform designed to help threat actors run malicious Google Ads campaigns while evading detection. The service filters out security researchers and automated scanners, showing benign content to reviewers while directing real users to phishing pages or crypto drainers, supported by visitor profiling, fraud scoring and geographic targeting. Operated for more than three years via Telegram, the platform combines ad launch tools with advanced traffic filtering to prolong the lifespan of fraudulent campaigns.

Anthropic Disrupts Mass AI Model Distillation Campaigns

Anthropic says it has uncovered large-scale distillation campaigns by DeepSeek, Moonshot and MiniMax aimed at extracting Claude’s capabilities to train competing models. The company identified more than 16 million exchanges conducted through around 24,000 fraudulent accounts, using proxy networks to evade access restrictions and harvest reasoning, coding and tool-use outputs.

Source: Anthropic

Fake Zoom Update Installs Hidden Teramind Surveillance Tool

Malwarebytes has identified a campaign using a counterfeit Zoom meeting page to trigger the silent download of a stealth-configured Teramind monitoring agent on Windows systems. The site simulates a glitchy video call before displaying a forced “update” prompt, which installs a preconfigured surveillance build designed to run invisibly and report to an attacker-controlled server. Because Teramind is legitimate commercial monitoring software, the activity may evade traditional antivirus detection while enabling persistent keystroke logging, screen capture and activity tracking.

Daily Coverage

Developments
Medusa Ransomware UseClaude Distillation CampaignsServ-U Rce PatchesShinyhunters Breaches
Vulnerabilities
CVE-2026-20127A Vulnerability In The Peering Authentication In Cisco Catalyst Sd-Wan Controller, Formerly Sd-Wan Vsmart, And Cisco Catalyst Sd-Wan Manager, Formerly Sd-Wan Vmanage, Could Allow An Unauthenticated, Remote Attacker To Bypass Authentication And Obtain Administrative Privileges On An Affected System. This Vulnerability Exists Because The Peering Authentication Mechanism In An Affected System Is Not Working Properly. An Attacker Could Exploit This Vulnerability By Sending Crafted Requests To An …CVE-2026-25108Filezen V5.0.0 To V5.0.10 (High)CVE-2025-40538CVE-2026-1357CVE-2026-25656Sinec Nms (High)CVE-2026-25655Sinec Nms (High)CVE-2026-2493CVE-2026-2491CVE-2026-21634Unifi Protect Application 6.1.79 (Medium)CVE-2026-21633Unifi Protect Application 6.1.79 (High)
Threat Groups
LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.Lazarus GroupLazarus Group is a North Korean statesponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.