Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationmass-credential-exposureransomware-group-operationthird-party-vendor-breach

Weekly threat intelligence roundup covering breaches, ransomware, and emerging AI-enabled tradecraft

Updated 3mo agoFirst seen Feb 23, 20267 sources

Reporting during the week of Feb. 23 highlighted multiple unrelated security incidents and research findings rather than a single cohesive event. France’s Ministry of Economy disclosed unauthorized access to the national bank account registry FICOBA, exposing data tied to ~1.2 million accounts (e.g., names, addresses, account identifiers, and in some cases tax-related identifiers), with officials attributing access to compromised government credentials. Separately, Advantest reported a ransomware intrusion following third-party unauthorized access, University of Mississippi Medical Center experienced a ransomware event that disrupted clinics and electronic medical records, and Ukraine’s National Bank reported a supply-chain exposure at a contractor supporting its collectible coin online store (customer registration data exposed; payment data reportedly unaffected). In Taiwan, Taipei Grand Hotel said a third party accessed internal systems without authorization during the Lunar New Year period; the hotel took networks offline for forensics and warned customers to be cautious of suspicious messages.

Threat-actor and technique reporting also described ongoing campaigns and emerging tradecraft. MuddyWater (Iran-aligned) was reported targeting MENA organizations in “Operation Olalampo,” using phishing lures with malicious Office documents/macros to deploy tooling including GhostFetch, HTTP_VIP, a Rust backdoor CHAR, and an implant dubbed GhostBackDoor, with one chain also deploying AnyDesk for remote access. Separately, reporting on DPRK-linked crypto operations described sustained, social-engineering-led targeting of the crypto ecosystem following the Bybit theft, including AI-assisted persona and communication crafting and laundering via mixing/OTC pathways. Additional research noted internet-wide scanning telemetry involving OAST/Interactsh callback domains and shifts toward cookie-based injection, while another item profiled PRC-attributed Lotus Blossom as an espionage actor (including discussion of the Notepad++ ecosystem incident) and a separate post provided general reconnaissance methodology rather than incident-specific intelligence.

Share:
Weekly threat intelligence roundup covering breaches, ransomware, and emerging AI-enabled tradecraft
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

22 events from the most recent confirmed update back to the earliest known activity.

22 EVENTS
Feb 23, 20264mo ago

Wynn breach details emerge with 800,000 records allegedly stolen

Sherpa Intelligence reported that ShinyHunters allegedly stole more than 800,000 Wynn records and demanded $1.5 million to prevent the data from being leaked.

Chrome zero-day CVE-2026-2441 is reported as exploited in the wild

Check Point reported that Chrome zero-day CVE-2026-2441 was being exploited in the wild, marking a notable active exploitation event.

Grandstream VoIP RCE vulnerability is publicly highlighted

Check Point's bulletin highlighted critical Grandstream VoIP remote code execution flaw CVE-2026-2329 as a significant newly reported vulnerability.

Researchers detail npm typosquatting worm targeting developer and AI secrets

Check Point summarized a supply-chain campaign in which an npm worm spread via typosquatting, stole developer and CI secrets, and targeted AI coding assistants to harvest LLM API keys.

Researchers report genAI-assisted FortiGate credential abuse campaign

A Russian-speaking actor was reported using commercial generative AI to scale credential abuse against FortiGate devices and then pivot to target Veeam servers.

Researchers show AI assistants can be abused as covert C2 proxies

Check Point researchers demonstrated that AI assistants such as Grok and Microsoft Copilot can be misused as covert command-and-control channels, highlighting a new AI-enabled threat technique.

National Bank of Ukraine contractor exposes coin store customer data

Check Point reported a supply-chain exposure at a contractor supporting the National Bank of Ukraine's collectible coin store, leaking customer registration data but not payment information.

Advantest reports ransomware after unauthorized network access

Advantest disclosed that an unauthorized party accessed parts of its network and that the incident involved ransomware, according to the Check Point bulletin and Sherpa roundup.

France discloses FICOBA registry breach affecting 1.2 million accounts

French authorities disclosed that attackers used stolen credentials to access the FICOBA national bank-account registry and exfiltrated data tied to 1.2 million accounts.

Feb 21, 20264mo ago

Taipei Grand Hotel is reported targeted in a cyberattack

Taiwan News published reporting that Taipei Grand Hotel had been targeted in a cyberattack, indicating a newly disclosed victim in Taiwan's hospitality sector.

Feb 19, 20264mo ago

University of Mississippi Medical Center detects ransomware attack

On February 19, 2026, the University of Mississippi Medical Center detected a ransomware attack that disrupted network and IT systems, including its Epic electronic medical record environment.

Feb 14, 20264mo ago

GreyNoise observes concentrated OAST scanning activity

Between February 14 and February 20, 2026, GreyNoise recorded 5,695 OAST domain occurrences across 3,882 sessions from 24 source IPs, with increased cookie-based injection and heavy Nuclei/loopback usage.

Jan 26, 20265mo ago

MuddyWater's Operation Olalampo is first observed

Group-IB said a new MuddyWater campaign dubbed Operation Olalampo was first observed on January 26, 2026, targeting organizations and individuals across the Middle East and North Africa with phishing and malware delivery.

Jan 1, 20266mo ago

DPRK social-engineering campaigns steal $37.5 million in early 2026

From January 1 to mid-February 2026, the DangerousPassword and Contagious Interview campaigns allegedly generated $37.5 million by tricking victims into installing malware that steals keys, seed phrases, and credentials.

Dec 31, 20256mo ago

DPRK-linked thefts reach a record $2 billion in 2025

The reporting states that DPRK-linked operators stole a record $2 billion in 2025, bringing cumulative known cryptocurrency thefts attributed to North Korea to more than $6 billion.

Dec 8, 20257mo ago

Cheyenne and Arapaho Tribes suffer disruptive intrusion

On December 8, 2025, the Cheyenne and Arapaho Tribes experienced an intrusion that disrupted schools and government operations; Rhysida later claimed responsibility according to the roundup.

Sep 1, 202510mo ago

Wynn breach reportedly begins with PeopleSoft access and employee credentials

Sherpa Intelligence reported that the ShinyHunters-linked breach of Wynn involved initial access in September 2025 through an Oracle PeopleSoft vulnerability and an employee's credentials.

Feb 21, 20251y ago

DPRK-linked actors steal $1.46 billion from Bybit

On February 21, 2025, North Korea-linked operators allegedly stole about $1.46 billion in cryptoassets from Dubai-based exchange Bybit, in what the report describes as the largest confirmed crypto theft to date.

Jan 1, 20251y ago

Lotus Blossom launches Notepad++ supply-chain operation

The group allegedly began a 2025-2026 supply-chain campaign targeting Notepad++ by manipulating update infrastructure to distribute trojanized updater components and deliver the Chrysalis backdoor via DLL sideloading.

Lotus Blossom targets a national certificate authority

In 2022, Lotus Blossom reportedly escalated from traditional intrusion methods to compromising a national certificate authority, marking a shift toward attacks on mechanisms of trust.

Jun 1, 20242y ago

UNC6201 exploits Dell RecoverPoint zero-day in the wild

Check Point reported that suspected Chinese threat actor UNC6201 has exploited Dell RecoverPoint for VMs zero-day CVE-2026-22769 since mid-2024, indicating a prolonged real-world exploitation window before public reporting.

Jan 1, 200917y ago

Lotus Blossom begins long-running cyber-espionage activity

Lotus Blossom is described as an APT active since at least 2009, conducting cyber-espionage operations primarily against government, military, and strategic-sector targets in the Asia-Pacific region.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

114 LINKEDOpen in app
Affected products
19 linked
Microsoft OfficeVirustotalTelegramWindowsOpensshConsulAnydeskNotepad++ZoomNginxOpenvpnNucleiOpensshUbuntuOpenvpnPeoplesoftNginxUbuntuConsul
Organizations
46 linked
Microsoft CorporationOracleGoogleAnchorfreeNotepad++China UnicomSeqriteGreyNoiseEpic Systems CorporationRapid7CensysDigitaloceanTeam CymruKT CorporationPalo Alto NetworksSOCRadarVirustotalKasperskyZoom CommunicationsByBitHashicorpVultrAdvantestBroadcomCloudSEKAdobeAnyDesk Software GmbHHostingerRouterHosting LLCGroup-IBEllipticPicus LabsAlliance Industries, LLC.M247OVH SASAuraLeaseWebFranTech SolutionsLos Angeles TimesPrivate Layer INCViet StorageWynn ResortsGhosty Networks LLCCloudzyDEMENIN B.V.31173 Services AB
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.