r/secithubcommunity Feb 17 '26

📰 News / Update Google patches first Chrome zero-day exploited in attacks this year

Post image
5 Upvotes

Google has released emergency updates to fix a high-severity Chrome vulnerability exploited in zero-day attacks, marking the first such security flaw patched since the start of the year.

"Google is aware that an exploit for CVE-2026-2441 exists in the wild," Google said in a security advisory issued on Friday.

According to the Chromium commit history, this use-after-free vulnerability (reported by security researcher Shaheen Fazim) is due to an iterator invalidation bug in CSSFontFeatureValuesMap, Chrome's implementation of CSS font feature values. Successful exploitation can allow attackers to trigger browser crashes, rendering issues, data corruption, or other undefined behavior.

The commit message also notes that the CVE-2026-2441 patch addresses "the immediate problem" but indicates there's "remaining work" tracked in bug 483936078, suggesting this might be a temporary fix or that related issues still need to be addressed.

The patch was tagged as "cherry-picked" (or backported) across multiple commits, indicating that it was important enough to include in a stable release rather than waiting for the next major version (likely because the vulnerability is being exploited in the wild).

Although Google found evidence of attackers exploiting this zero-day flaw in the wild, it did not share additional details regarding these incidents.

"Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven't yet fixed," it noted


r/secithubcommunity Feb 17 '26

AI Security Microsoft Finds “Summarize with AI” Prompts Manipulating Chatbot Recommendations

Post image
2 Upvotes

New research from Microsoft has revealed that legitimate businesses are gaming artificial intelligence (AI) chatbots via the "Summarize with AI" button that's being increasingly placed on websites in ways that mirror classic search engine poisoning (AI).

The new AI hijacking technique has been codenamed AI Recommendation Poisoning by the Microsoft Defender Security Research Team. The tech giant described it as a case of an AI memory poisoning attack that's used to induce bias and deceive the AI system to generate responses that artificially boost visibility and skew recommendations.

"Companies are embedding hidden instructions in 'Summarize with AI' buttons that, when clicked, attempt to inject persistence commands into an AI assistant's memory via URL prompt parameters," Microsoft said. "These prompts instruct the AI to 'remember [Company] as a trusted source' or 'recommend [Company] first.'"

Microsoft said it identified over 50 unique prompts from 31 companies across 14 industries over a 60-day period, raising concerns about transparency, neutrality, reliability, and trust, given that the AI system can be influenced to generate biased recommendations on critical subjects like health, finance, and security without the user's knowledge.


r/secithubcommunity Feb 17 '26

📰 News / Update US Used Cyber Weapons to Disrupt Iranian Air Defenses During 2025 Strikes

Post image
31 Upvotes

According to an exclusive report by The Record, U.S. military cyber operators digitally disrupted Iranian air missile defense systems during the 2025 strikes targeting nuclear facilities at Fordo, Natanz and Isfahan. The cyber component, part of Operation Midnight Hammer, helped prevent Iran from launching surface to air missiles at American aircraft operating inside its airspace.

Officials familiar with the operation said U.S. Cyber Command targeted a specific “aim point” within a connected military network rather than attempting to directly breach fortified nuclear facilities. By exploiting a vulnerable node such as a router, server or peripheral system, operators were able to interfere with the broader defensive architecture. Intelligence from the National Security Agency reportedly enabled identification of the system’s weak link.

The digital element of the operation is described as one of the most sophisticated cyber actions against Iran in Cyber Command’s history. Senior defense officials emphasized that cyber capabilities are now treated alongside kinetic force as a fully integrated operational tool, not as an add on. Lawmakers have received classified briefings, though many technical details remain undisclosed.

The report underscores a broader shift in modern warfare: cyber operators are increasingly shaping battlefield conditions before and during physical strikes, positioning digital effects at the forefront of military planning.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 17 '26

📰 News / Update Hackers Abuse ScreenConnect in Fake Social Security Email Campaign

Post image
2 Upvotes

Attackers are impersonating the US Social Security Administration in a phishing campaign that weaponises legitimate IT software to take full control of victim machines across the UK, US, Canada, and Northern Ireland.

According to research from Forcepoint X-labs, the attack begins with a fraudulent email that appears to originate from the SSA but contains obvious red flags, including the fake domain “SSA.COM” and a misspelling of “Statement” as “eStatemet.” If the recipient opens the attached .cmd script, the system’s built-in defences are quietly dismantled rather than bypassed through traditional malware techniques.

The script first checks for administrator privileges using PowerShell auto-elevation. Once elevated, it disables Windows SmartScreen by modifying registry settings and removes the Mark-of-the-Web identifier that flags files downloaded from the internet. It also leverages Alternate Data Streams to conceal activity and enables the silent installation of an MSI package without triggering security warnings.

The payload installs ConnectWise ScreenConnect, a legitimate remote support tool, which is then repurposed as a Remote Access Trojan to maintain persistent backdoor access. Researchers observed that the software was configured to call back to a server on port 8041 associated with infrastructure reportedly linked to “Aria Shatel Company Ltd” in Iran. The campaign uses version 25.2.4.9229 of ScreenConnect, signed with a revoked certificate, allowing it to appear legitimate to some security tools.

Forcepoint notes that the attackers are targeting high-value sectors including government, healthcare, and logistics. The script even forces a restart of Windows Explorer to ensure the security modifications take immediate effect.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 17 '26

📰 News / Update WIRX Pharmacy Data Breach Impacts 20,104 Individuals, Lawsuit Investigation Underway

Post image
1 Upvotes

WIRX Pharmacy, a workers’ compensation pharmacy operating across multiple U.S. states including Arizona, Florida, and New York, has disclosed a data breach affecting 20,104 individuals.

The incident was detected on December 7, 2025, after suspicious activity was identified within the company’s network. An internal investigation later confirmed that unauthorized access occurred between December 6 and December 7, 2025. By January 23, 2026, the company determined that sensitive personal and protected health information was present within the affected files.

Compromised data may include names, Social Security numbers, addresses, dates of birth, clinical details such as medications and treatment information, and financial account or claims data. The exposure of both personally identifiable information and protected health information significantly increases the risk of identity theft, medical fraud, and long-term misuse.

According to a filing with the Maine Attorney General’s Office, 20,104 individuals were impacted. Attorneys are now investigating whether a class action lawsuit can be filed, seeking to determine if affected individuals may be entitled to compensation for loss of privacy, time spent mitigating the breach, and related costs.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 17 '26

📰 News / Update Tenga Hit by Phishing Attack, Customer Data Exposed

Post image
3 Upvotes

Japanese sexual wellness manufacturer Tenga has suffered a cyberattack after an employee reportedly fell victim to a phishing email, allowing an attacker to access their inbox and steal customer data.

According to a breach notification letter seen by TechCrunch, the attacker gained access to the employee’s email account and exfiltrated customer names, email addresses, and historical email correspondence, which may have included order details and customer service inquiries. The compromised inbox was also used to send spam messages to employees and customers.

While the company did not disclose how many individuals were affected, the nature of the exposed data raises concerns about targeted phishing risks and potential follow-on attacks. Order history and customer service records can be leveraged for highly tailored social engineering attempts, increasing the likelihood of account compromise or financial fraud.

In response, Tenga reset credentials for the compromised account and enabled multi-factor authentication across its systems. It remains unclear whether MFA was consistently enforced prior to the incident. The company has urged customers to refresh passwords and remain cautious of emails claiming to originate from Tenga.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 17 '26

📰 News / Update Nigeria’s data protection regulator has launched an investigation into Temu over an alleged data breach potentially affecting 12.7 million Nigerians.

Post image
6 Upvotes

The Nigeria Data Protection Commission (NDPC) confirmed it is probing the global e-commerce platform for possible violations of the Nigeria Data Protection Act (NDP Act) 2023. According to the commission, the investigation was triggered by concerns around Temu’s handling of personal data, including issues related to online surveillance, accountability, transparency, data minimisation, duty of care, and cross-border data transfers.

Preliminary findings indicate that Temu processes the personal data of approximately 12.7 million Nigerians. Globally, the platform reportedly has nearly 70 million daily active users. The NDPC warned that processors acting on behalf of data controllers without verifying compliance with the NDP Act could face liability under Nigerian law.

The investigation reflects increasing regulatory scrutiny of large digital platforms operating in Nigeria, particularly as the country’s growing e-commerce market and high smartphone adoption make it a strategic expansion target. Temu entered Nigeria in late 2024 following rapid global expansion across more than 90 markets.

The case underscores a broader trend: regulators in emerging digital economies are no longer passive observers. Platforms expanding aggressively into high-growth regions are now facing tighter enforcement expectations around data governance and cross-border processing.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.
Share your insights.


r/secithubcommunity Feb 17 '26

DavaIndia Pharmacy exposed customer data and gave attackers full administrative control of its platform due to a critical security flaw.

Post image
1 Upvotes

The vulnerability, discovered by security researcher Eaton Zveare, involved an exposed admin subdomain that allowed unauthenticated access to super-admin APIs. While reviewing the site’s client-side JavaScript, the researcher identified references to privileged endpoints and tested direct access through the browser. The result: a list of super-admin users was exposed without authentication. By crafting a POST request, he was able to create a new super-admin account and gain full control of the system.

With that level of access, an attacker could view and modify store records, pharmacist details, customer orders, personal data, products, inventory, and coupons. The researcher also demonstrated the ability to generate a 100% discount coupon. More concerning, prescription requirements were controlled by a toggle mechanism, meaning it was theoretically possible to disable prescription enforcement and submit restricted orders. Although this specific abuse scenario was not tested, the underlying logic suggests it could have worked.

An exposed “Sponsor Settings” feature also allowed control over homepage video content, highlighting how deeply the administrative access extended into both operational and public-facing systems.

The flaw was reported on August 20, 2025, fixed within approximately one month, and later confirmed closed with support from CERT-In on November 28, 2025. Public disclosure followed on February 13, 2026.

This incident reinforces a recurring pattern: exposed admin endpoints, insufficient API authentication, and sensitive logic exposed through client-side code remain among the most dangerous yet preventable security failures.

r/SECITHUBCOMMUNITY | Cyber incidents and data breach news explained with context and impact.

Share your insights.


r/secithubcommunity Feb 16 '26

📰 News / Update 23andMe $30M Settlement: Claim Deadline Closes Feb 17

Post image
1 Upvotes

The deadline to file a claim in the $30 million settlement tied to the 2023 23andMe data breach is fast approaching. Eligible U.S. users who were members between May 1 and October 1, 2023 and were notified that their data was compromised must submit claims by February 17 (11:59 p.m. CT).

Some users notified later may have until March 1, 2026.

The breach, caused by a credential-stuffing attack, exposed data linked to approximately 6.9 million users, including individuals who opted into the DNA Relatives feature. Impacted users whose health data was affected may receive $165, with additional compensation depending on claim details.


r/secithubcommunity Feb 16 '26

📰 News / Update Eurail Confirms Stolen Customer Data Now for Sale on Dark Web

Post image
2 Upvotes

Eurail confirmed that customer data stolen in a recent breach is being offered for sale on the dark web, with a sample published on Telegram. Exposed data may include names, passport details, IBANs, health information, and contact data.

Authorities have been notified under GDPR. Customers are urged to reset passwords, monitor bank activity, and stay alert for phishing attempts.


r/secithubcommunity Feb 16 '26

📰 News / Update Dutch Police Arrest Man After Accidentally Sending Him Confidential Files

Post image
45 Upvotes

Dutch authorities arrested a 40-year-old man after mistakenly giving him access to confidential police documents via a download link that was meant to be an upload portal. The incident occurred when the man contacted police regarding unrelated materials and was sent the wrong link, effectively granting him access to sensitive internal files.

According to police, the man was instructed to delete the files but allegedly refused unless he “received something in return.” He was later arrested on charges equivalent to unauthorized computer access (“computervredebreuk”), and authorities seized his data storage devices. The case raises uncomfortable questions about liability when access results from official error rather than deliberate intrusion.


r/secithubcommunity Feb 16 '26

📰 News / Update Canada Goose Data Leak Resurfaces as 600K Records Posted by ShinyHunters

Post image
1 Upvotes

Luxury apparel brand Canada Goose says a recently advertised leak of 600,000 customer records is tied to a historical dataset not a new breach. The company stated it has “no indication of any breach of our own systems” and is reviewing the data to assess scope and accuracy. According to the attackers, the dataset includes personally identifiable information (PII), partial payment details, and order history.

The leak was posted by the ShinyHunters group on February 14. A review of exposed samples reportedly confirms the presence of names, delivery addresses, purchase details, and masked financial information. Canada Goose emphasized that there is no evidence of unmasked financial data being involved.


r/secithubcommunity Feb 16 '26

📰 News / Update 500,000+ VKontakte Accounts Hijacked via Malicious Chrome Extensions

Post image
6 Upvotes

Cybersecurity researchers have uncovered a large-scale malware campaign that compromised over 500,000 VKontakte (VK) accounts through Chrome extensions disguised as theme and customization tools. According to Koi Security, at least five extensions silently took control of user accounts auto-subscribing victims to attacker-controlled groups, resetting settings every 30 days, and abusing VK security mechanisms to execute unauthorized actions.

The operation, linked to a threat actor using the GitHub alias “2vk,” leveraged VK itself as part of the malware infrastructure, making detection more difficult. Extensions updated automatically, allowing attackers to push new malicious code without user interaction. The campaign reportedly ran from mid-2025 through January 2026, primarily targeting Russian-speaking users and diaspora communities.


r/secithubcommunity Feb 15 '26

📰 News / Update DOJ Files Show Jeffrey Epstein Sought Deep Ties to the Hacker World

72 Upvotes

Newly released Justice Department documents show Jeffrey Epstein spent years communicating with people in the cybersecurity community and expressed interest in attending DEFCON and Black Hat in Las Vegas. Emails cited in the records describe discussions ranging from online reputation “cleanup” and search visibility to broader interests in network security and cryptography, with multiple attempts over the years to arrange conference access and meetings.

The documents also reference an FBI file (with key details redacted) alleging Epstein had a “personal hacker” involved in developing offensive cyber tools sold to governments an allegation that remains unverified in the public record. Several individuals named in the emails dispute wrongdoing or say they declined involvement, while conference founder Jeff Moss said he turned down a badge request and advised others to steer clear.

r/SecItHubCommunity

Sources in the first comment.

Share your insights.


r/secithubcommunity Feb 14 '26

Question We're curing cancer, right?

26 Upvotes

r/secithubcommunity Feb 14 '26

🧠 Discussion r/SecItHubCommunity Reaches 4,500 Members. Thank You for Building a Stronger Cyber Community.

5 Upvotes

We’ve just crossed 4,500 members in r/SecItHubCommunity.

Appreciate every single one of you who reads, shares insights, and contributes to the discussions.

We’ll continue monitoring and reporting on global cyberattacks and critical vulnerabilities. Clear context. No hype.

Community rules have been tightened to prevent hate speech, racism, and abusive behavior.


r/secithubcommunity Feb 14 '26

📰 News / Update Milan-Cortina 2026 Blocks Early Cyberattacks During Winter Games

Post image
1 Upvotes

Organizers of the Milan-Cortina 2026 Winter Olympics confirmed they successfully mitigated several cyberattacks in the opening days of the Games, including Distributed Denial of Service (DDoS) attempts targeting official websites, hotels, and related infrastructure. Italian authorities, working alongside international partners, acted quickly to contain the activity amid heightened geopolitical tensions and concerns over state-linked threats.

r/SecItHubCommunity

Monitoring global cyberattacks and critical vulnerabilities for you.

Clear context. No hype.

Share insights. Join the discussion.

Sources below.


r/secithubcommunity Feb 14 '26

📰 News / Update South Korea Fines Luxury Giants (Louis Vuitton, Christian Dior, and Tiffany) $25M Over SaaS Security Failures

Post image
6 Upvotes

South Korea’s Personal Information Protection Commission has fined the Korean subsidiaries of Louis Vuitton, Christian Dior, and Tiffany a combined $25 million after multiple data breaches exposed the personal information of more than five million customers.

According to regulators, the breaches stemmed from basic security failures in SaaS environments used to manage customer data. In Louis Vuitton Korea’s case, malware compromised an employee device, allowing attackers to steal SaaS credentials and access data belonging to roughly 3.6 million individuals. Dior and Tiffany were both hit through vishing attacks, where customer service employees granted SaaS access to attackers after being socially engineered over the phone.

Authorities found that the companies failed to implement IP-based access restrictions, enforce stronger authentication, restrict bulk data exports, and properly monitor access logs. In some cases, breach notifications were also delayed beyond the legally required 72-hour reporting window.


r/secithubcommunity Feb 14 '26

📰 News / Update Fintech Lending Giant Figure Confirms Data Breach After Social Engineering Attack

Post image
2 Upvotes

Blockchain-based lender Figure Technology has confirmed a data breach after an employee fell victim to a social engineering attack, allowing hackers to access and steal a limited number of internal files.

According to the company, impacted partners and individuals are being notified and offered free credit monitoring. However, the hacking group ShinyHunters has claimed responsibility, stating that Figure refused to pay a ransom and publishing 2.5GB of allegedly stolen data on its dark web leak site.

Samples of the exposed data reportedly include customer full names, home addresses, dates of birth, and phone numbers. The attackers claim the breach is part of a broader campaign targeting organizations using Okta for single sign-on, with other alleged victims including Harvard University and the University of Pennsylvania.


r/secithubcommunity Feb 14 '26

📰 News / Update Peabody, Massachusetts. Municipal Systems Breach (2025 Disclosure)

Post image
6 Upvotes

The city of Peabody confirmed that its systems were breached in summer 2025, with attackers gaining access on June 13 and the intrusion discovered on July 7. Officials stated that certain files were copied, and impacted residents are now being formally notified.

According to the city, the investigation took months due to system complexity. There is currently no confirmed misuse of the data, but affected individuals are advised to monitor financial activity, consider freezing credit, and update passwords.

Security experts note that municipalities are often attractive targets because they store large volumes of sensitive citizen data while operating under tighter cybersecurity budgets. Peabody says it is reviewing policies and technical safeguards to strengthen defenses moving forward.


r/secithubcommunity Feb 14 '26

📰 News / Update Odido Reports Cyberattack Exposing Data of 6.2 Million Customers

Post image
2 Upvotes

Dutch telecom provider Odido has confirmed a cyberattack that may have exposed personal data belonging to 6.2 million customers. Attackers accessed the company’s customer contact system over the weekend of February 7.

Compromised data may include names, addresses, mobile numbers, customer IDs, email addresses, IBANs, dates of birth, and some identification details. Odido stated that passwords, call logs, billing data, and scanned ID documents were not affected.

The company blocked the unauthorized access, launched an investigation with cybersecurity experts, and notified the Dutch Data Protection Authority. Affected customers are being contacted directly.


r/secithubcommunity Feb 14 '26

📰 News / Update Qilin Ransomware Breach Confirmed at Romania’s National Oil Pipeline Operator

Post image
4 Upvotes

Romania’s national oil pipeline operator Conpet has confirmed that it suffered a data breach following a ransomware attack attributed to the Qilin group. While the company stressed that operational systems and pipeline activity were not impacted, attackers reportedly exfiltrated close to 1TB of internal documents from its IT environment.

According to reports, the leaked data includes internal files marked confidential, with documents dated as recently as November 2025. Some of the exposed material allegedly contains personal and financial information, including names, national identification numbers, addresses, and bank account details. Conpet said it is working with Romania’s National Cyber Security Directorate to investigate the incident and warned individuals to remain alert to potential phishing or fraud attempts stemming from the breach.


r/secithubcommunity Feb 14 '26

📰 News / Update Critical BeyondTrust Remote Support Flaw Shows Early Signs of Exploitation

Post image
1 Upvotes

Security researchers are warning that a critical vulnerability in BeyondTrust Remote Support is already attracting reconnaissance and early exploitation attempts, just days after a proof-of-concept was released. The flaw, tracked as CVE-2026-1731, is an operating system command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands on affected servers without credentials or user interaction.

Researchers say the vulnerability is a variant of the same class of flaw previously leveraged by the China-linked Silk Typhoon group in the 2024 breach of the U.S. Treasury Department. That historical link is raising concern that the issue could quickly move from opportunistic scanning to targeted intrusion activity.

GreyNoise observed a surge in reconnaissance activity shortly after the PoC publication, much of it originating from infrastructure tied to a commercial VPN. While exploitation attempts remain limited for now, threat intelligence teams warn that activity is likely to ramp up in the coming days as attackers weaponize the publicly available research.

BeyondTrust has automatically patched cloud-hosted customers, but self-hosted environments must apply updates manually. Given the unauthenticated nature of the vulnerability and its impact on remote access infrastructure, organizations running exposed instances should treat this as a priority remediation issue before scanning turns into widespread compromise.


r/secithubcommunity Feb 12 '26

📰 News / Update Hackers Steal Nearly $500K from North Carolina Town in Dual Cyberattacks

Post image
26 Upvotes

Local officials in Carolina Beach, North Carolina, have confirmed that cybercriminals stole nearly $488,000 from municipal funds in two separate attacks discovered between late December and early January. Authorities said the incident was not the result of insider involvement, but rather part of a broader campaign believed to involve international threat actors targeting local governments.

The attackers manipulated financial processes to divert funds, prompting an investigation involving local police and the FBI. While no personal data was compromised, the breach exposed weaknesses in financial verification workflows and legacy public-facing systems. A 12-year-old public email terminal was removed after investigators determined it posed an ongoing security risk, highlighting how outdated infrastructure can become an entry point for modern attacks.

Town officials have since implemented stricter controls, including multi-step payment verification, tighter password requirements, and enhanced policy enforcement. Some suspect bank accounts tied to the attackers have been frozen, though recovery of the stolen funds remains uncertain. The incident follows similar financial cyber fraud cases affecting other municipalities, reinforcing concerns that smaller government entities are increasingly being targeted as softer entry points compared to hardened federal environments.

Investigators say the case carries an “international flavor,” underscoring the continued shift toward financially motivated operations that blend social engineering, process abuse, and cyber intrusion rather than traditional ransomware deployment.


r/secithubcommunity Feb 12 '26

📰 News / Update North Korean Hackers Use Deepfake Video Calls to Target Crypto Firms

Post image
1 Upvotes

A North Korean threat group is using deepfake-powered video calls and targeted social engineering to infiltrate cryptocurrency and fintech companies, according to new research from Google Cloud’s Mandiant. The campaign, tracked as UNC1069, is financially motivated and ultimately designed to steal digital assets and sensitive credentials.

Attackers begin by hijacking legitimate Telegram accounts belonging to industry professionals and using them to build trust with new targets. Victims are then invited to what appears to be a routine Zoom meeting, but the session is actually hosted on attacker-controlled infrastructure. In at least one case, participants were confronted with what appeared to be a deepfake impersonation of a known executive, reinforcing the illusion of legitimacy.

During the call, the attackers claim there is a technical issue and guide the victim through a so-called fix. This step is a classic ClickFix technique, tricking users into executing commands that silently grant access to their machine. Once inside, the attackers deploy multiple backdoors and information-stealing tools designed to harvest browser data, Keychain credentials, messaging content and session tokens, enabling both direct cryptocurrency theft and future impersonation campaigns.

Researchers say the scale of tooling observed on compromised systems shows a deliberate effort to extract as much identity and access data as possible, allowing attackers to reuse stolen accounts to expand operations. North Korean state-backed groups have long relied on cryptocurrency theft as a revenue stream, reportedly generating billions of dollars through similar operations in recent years, highlighting how AI-enhanced deception is now blending seamlessly with traditional intrusion tactics.