Inside the Fix: Analysis of In-the-Wild Exploit of CVE-2026-21513#CVE_2026_21513 #APT28 https://www.akamai.com/blog/security-research/2026/feb/inside-the-fix-cve-2026-21513-mshtml-exploit-analysis
Operation MacroMaze: new APT28 campaign using basic tooling and legit infrastructure#APT28 https://lab52.io/blog/operation-macromaze-new-apt28-campaign-using-basic-tooling-and-legit-infrastructure/
EventLog-in: Propagating With Weak Credentials Using the Eventlog Service in Microsoft Windows (CVE-2025-29969)#CVE_2025_29969 https://www.safebreach.com/blog/safebreach_labs_discovers_cve-2025-29969/
New Keenadu backdoor found in Android firmware, Google Play apps#Keenadu https://www.bleepingcomputer.com/news/security/new-keenadu-backdoor-found-in-android-firmware-google-play-apps/
Not Safe for Politics - Cellebrite Used on Kenyan Activist and Politician Boniface Mwangi#Cellebrite https://citizenlab.ca/research/cellebrite-used-on-kenyan-activist-and-politician-boniface-mwangi/
LummaStealer Is Getting a Second Life Alongside CastleLoader#LummaStealer #CastleLoader https://www.bitdefender.com/en-us/blog/labs/lummastealer-second-life-castleloader
Old-School IRC, New Victims: Inside the Newly Discovered SSHStalker Linux Botnet#SSHStalker https://flare.io/learn/resources/blog/old-school-irc-new-victims-inside-the-newly-discovered-sshstalker-linux-botnet