Cybersecurity Weekly Roundup: February 16-22, 2026
Cybersecurity saw major incidents from February 16 to 22, 2026. PayPal disclosed a breach exposing SSNs and DOBs for months. Google patched a Chrome zero-day under active exploit. Cloudflare faced a 6-hour global outage from BGP errors. Ransomware and new malware also surged.
Hellcat ransomware hit Ascom, stealing 44GB via Jira creds from infostealers. AI-powered attacks compromised 600+ FortiGate firewalls. BeyondTrust RCE saw heavy scanning from one IP. These events highlight rising enterprise risks.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
Breach notifications poured in. SpyX spyware leaked 2 million users’ data, including Apple creds. California Cryobank lost customer PII via SQL injection. Noodlophile stealer evolved with fake jobs and DLL sideloading.
Key Threats This Week
VoidLink Linux malware used LLM for multi-cloud rootkits. Raspberry Robin worm tied to 200 flux domains. Grok and Copilot abused as C2 channels.
Vendors rushed patches. Ivanti EPMM, Splunk, Windows Admin Center fixed critical flaws. Chrome updated for CVE-2026-2441 use-after-free. Many exploits hit wild already.
Cloudflare’s outage stemmed from BYOIP password rotation failure. It withdrew routes globally for hours. No cyberattack, but availability proved fragile.
Vulnerabilities Table
| CVE ID | Product | Severity | Status |
|---|---|---|---|
| CVE-2026-1281 | Ivanti EPMM | 9.8 Critical | Actively exploited |
| CVE-2026-20140 | Splunk Enterprise | High | Session hijacking |
| CVE-2025-26909 | WP Ghost Plugin | 9.6 Critical | RCE on 200k sites |
| CVE-2025-26512 | NetApp SnapCenter | 9.9 Critical | Priv esc |
| CVE-2026-2441 | Google Chrome | High 8.8 | Zero-day exploited |
| N/A | BeyondTrust | Critical | WebSocket RCE |
| N/A | Windows Admin Center | Critical | System takeover |
PayPal breach lasted July to December 2025 via loan app error. Attackers grabbed PII for fraud.
Chrome fix rolled to v145.0.7632.75. Zero-day CVE-2026-2441 allowed sandbox escape via malicious pages.
Action Items
- Patch Chrome, Ivanti, Splunk immediately.
- Scan for BeyondTrust WebSocket scans from 193.24.123.42.
- Review Jira creds after Hellcat ransomware.
- Block Raspberry Robin domains (.wf, .pm TLDs).
Stay vigilant on AI C2 abuse and evolved stealers.
FAQ
Loan app error exposed SSNs/DOBs July-Dec 2025. Six-month detection lag.
CVE-2026-2441 use-after-free in CSS. Patched Feb 13, active exploits confirmed.
BYOIP password rotation withdrew BGP routes. Six hours global impact, no attack.
Hellcat stole 44GB from Ascom via infostealer Jira creds.
Over 10 critical, including Ivanti RCE and WP Ghost 9.6 flaw.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages