Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalogransomware-group-operationenforcement-action

Security roundups covering multiple unrelated breaches, exploited vulnerabilities, and malware activity

Updated 3mo agoFirst seen Feb 15, 20263 sources

The referenced items are weekly newsletter/roundup posts that aggregate multiple, unrelated cybersecurity developments rather than reporting a single discrete incident. They highlight a mix of data breaches, ransomware, active exploitation and KEV additions, and malware campaigns—including mentions of BeyondTrust RS/PRA vulnerabilities (including CVE-2026-1731) being exploited, CISA adding various flaws to the Known Exploited Vulnerabilities (KEV) catalog, and ongoing malware activity such as LummaStealer, NetSupport RAT targeting, and Linux botnet activity (e.g., SSHStalker).

Separately, the roundup coverage also includes public-sector and critical-service disruptions and regulatory action: a reported cyberattack on the European Commission’s mobile device management (MDM) environment with potential exposure of staff contact details, a ransomware incident disrupting Senegal’s national identity services, and an Australian court penalty against FIIG Securities tied to inadequate cybersecurity controls following a prior ransomware breach and data exposure. Overall, the content is best treated as situational awareness across many stories, not as a cohesive incident requiring a single-issue response plan.

Share:
Security roundups covering multiple unrelated breaches, exploited vulnerabilities, and malware activity
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Feb 20, 20264mo ago

India's AI-generated content handling rules take effect

India introduced formal rules for labeling and handling AI-generated content, with the measures becoming effective on 2026-02-20. The policy was highlighted as a notable regulatory development in the roundup.

Feb 15, 20264mo ago

Security Affairs publishes malware roundup covering new campaigns and tools

On 2026-02-15, Security Affairs published Malware Newsletter Round 84, aggregating reporting on campaigns and malware including NetSupport RAT activity, ZeroDayRAT, SSHStalker, AgreeToSteal, LummaStealer, CastleLoader, BADIIS, and VoidLink-linked operations. The piece compiled previously reported technical developments rather than announcing one discrete incident.

Security Affairs highlights active exploitation and major breach disclosures

On 2026-02-15, Security Affairs' weekly international newsletter summarized ongoing exploitation of multiple vulnerabilities, recent vendor patches, and breach disclosures affecting organizations including Odido, ApolloMD, Conduent/Volvo Group, Figure, Flickr, and Senegal’s national ID-related office. The item was a roundup rather than a single newly reported incident.

Feb 13, 20264mo ago

Daren Li sentenced in absentia for $73 million pig-butchering scam

In the United States, Daren Li was sentenced in absentia to 20 years in prison for a $73 million cryptocurrency pig-butchering fraud scheme. The case involved laundering nearly $60 million through U.S. shell companies.

Australia fines FIIG Securities over cybersecurity control failures

Australian authorities imposed a landmark AU$2.5 million penalty on FIIG Securities, plus AU$500,000 in legal costs, over inadequate cybersecurity controls. The action was tied to control failures that preceded a 2023 ransomware breach exposing 385GB of client data.

Senegal identity services disrupted by ransomware incident

Senegal’s Directorate of File Automation suffered a ransomware attack that halted identity card production and disrupted national ID, passport, and electoral services. Authorities said personal data was not compromised and the investigation remained ongoing.

Jan 30, 20265mo ago

European Commission contains MDM breach within nine hours

The European Commission said the January 30 intrusion was contained within nine hours of detection. Its disclosure indicated the impact was limited to data exposure involving staff contact details.

European Commission mobile device management system attacked

On 2026-01-30, the European Commission disclosed a cyberattack affecting its mobile device management system. The incident may have exposed staff names and mobile phone numbers, but officials said no devices were compromised.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

40 LINKEDOpen in app
Threat actors
4 linked
Affected products
7 linked
AndroidAndroidIosIosWeb Help DeskWeb Help DeskMicrosoft Office
Organizations
16 linked
Security AffairsBeyondtrustVolvoSolarWindsConduentFortinetIvantiZoho CorporationAppleMicrosoft CorporationFlickrGoogleApolloMDOdidoFIIG SecuritiesFigure
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.