Isometric network nodes illustrating critical cyber flaws and AI risks.

Daily Cybersecurity News - February 10, 2026

BeyondTrust Patches Critical Access Flaw

Critical

Executive Summary

BeyondTrust has patched a critical remote code execution (RCE) vulnerability, identified as CVE-2026-1731, in its Remote Support and Privileged Remote Access products. The flaw allows unauthenticated, remote attackers to execute arbitrary OS commands; patches are now available and should be applied immediately.

Vulnerability Details

  • Affected Product: BeyondTrust Remote Support (RS) versions 25.3.1 and prior and Privileged Remote Access (PRA) versions 24.3.4 and prior.
  • Identifier: CVE-2026-1731
  • CVSS Score: 9.9 (Critical).
  • Exploitation Status: No known active exploitation.

Risk & Impact

  • Triage: Urgent. This vulnerability allows for full system compromise without authentication or user interaction.
  • Attack Vector: An unauthenticated remote attacker can send a specially crafted client request to a vulnerable instance to execute operating system commands.
  • Ease of Exploit: Straightforward. Technical details are being withheld to allow time for patching.

Action Plan

  • Immediate Action: On-premise customers should upgrade to Remote Support version 25.3.2+ or Privileged Remote Access version 25.1.1+. Note: Instances running versions older than RS 21.3 or PRA 22.1 must perform a major version upgrade before the security patch can be applied.
  • Workaround: All SaaS instances were automatically patched by BeyondTrust on February 2, 2026. Self-hosted customers must apply patches manually if automatic updates are disabled.

Relevant professional terms

Remote Code Execution (RCE)
A class of software vulnerability that allows a malicious actor to execute arbitrary commands or code on a remote machine over a network.
Authentication
The process of verifying the identity of a user, process, or device, often as a prerequisite to allowing access to resources in a system.
Source: SecurityWeek

Fortinet Patches Critical Code Execution Flaw

Critical

Executive Summary

Fortinet has released security updates to address a critical SQL injection vulnerability, identified as CVE-2026-21643, in its FortiClientEMS software. The now-Patched flaw could allow an unauthenticated, remote attacker to execute arbitrary code on affected systems.

Vulnerability Details

  • Affected Product: FortiClientEMS version 7.4.4.
  • Identifier: CVE-2026-21643
  • CVSS Score: 9.1 (Critical).
  • Exploitation Status: No known active exploitation at the time of disclosure.

Risk & Impact

  • Triage: Immediate patching is required due to the critical severity and potential for unauthenticated remote code execution.
  • Attack Vector: An unauthenticated attacker can exploit this SQL injection flaw by sending specially crafted HTTP requests to a vulnerable FortiClientEMS server.
  • Ease of Exploit: The vulnerability is exploitable remotely without any authentication, suggesting a lower complexity for a potential attacker.

Action Plan

  • Immediate Action: Upgrade FortiClientEMS to version 7.4.5 or above.
  • Workaround: No specific workarounds have been provided by the vendor; upgrading is the recommended solution.
  • Detection: Administrators should monitor logs for unusual HTTP requests to the admin interface and consider limiting its exposure to the internet.

Relevant professional terms

SQL Injection (SQLi)
A web security vulnerability that allows an attacker to interfere with the queries that an application makes to its database, potentially allowing them to view or modify data.
Arbitrary Code Execution (ACE)
An attacker's ability to run any commands or code of their choice on a target machine or process.

Chinese Cyberspies Infiltrate Singapore Telcos

Executive Summary

A China-linked espionage group, UNC3886, executed a targeted campaign against Singapore's four largest telecom providers. The attackers utilized sophisticated tools to gain access, but a coordinated national response reportedly prevented service disruption and theft of sensitive customer data.

Attack Overview

  • Attack Path: The group exploited a zero-day vulnerability in perimeter firewalls to gain initial access, then deployed rootkits to maintain stealthy, persistent access.
  • Attacker: UNC3886, a suspected China-nexus espionage actor.

Impact Assessment

  • Data Stolen: A small amount of technical network data was exfiltrated, likely for reconnaissance to plan future intrusions. No sensitive customer data was reported stolen.

Strategic Takeaway

This incident highlights the strategic targeting of critical telecommunications infrastructure by nation-state actors who exploit zero-day vulnerabilities in edge devices to conduct espionage.

Relevant professional terms

Zero-Day Exploit
A cyberattack that takes advantage of a previously unknown software vulnerability for which no patch or fix is currently available.
Rootkit
A type of malicious software designed to gain unauthorized, privileged access to a computer system while actively hiding its presence from administrators and security tools.

Dutch Agencies Breached Via Ivanti Flaw

Executive Summary

Dutch authorities, including the Data Protection Authority (AP) and the Council for the Judiciary (Rvdr), confirmed a data breach after attackers exploited critical zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM). The incident exposed employee contact information and is part of a wider campaign affecting European government institutions. Crucially, investigations revealed a "soft delete" architectural failure: data marked as deleted was not scrubbed from the database, allowing attackers to access historical records of former employees and decommissioned devices.

Attack Overview

  • Attack Path: Threat actors exploited two critical code injection vulnerabilities, CVE-2026-1281 and CVE-2026-1340, to achieve unauthenticated remote code execution.

Impact Assessment

  • Data Stolen: Exposed data includes employee names, business email addresses, and phone numbers.

Strategic Takeaway

Internet-facing management interfaces for enterprise solutions remain high-value targets, and their compromise can lead to significant data exposure even without a full network breach.

Relevant professional terms

Zero-Day Vulnerability
A flaw in software or hardware that is discovered and exploited by attackers before the vendor becomes aware of it or can release a patch.
Remote Code Execution (RCE)
An attack where a threat actor can remotely execute commands of their choosing on a compromised machine over a network.

Mobile Spyware Grants Total Device Control

Executive Summary

A new commercial spyware kit, ZeroDayRAT, is being sold on Telegram, offering cybercriminals full remote control over compromised Android and iOS devices. The malware enables comprehensive data theft, real-time surveillance, and financial theft.

Key TTPs

  • Initial Access: Primarily delivered via smishing, but also uses phishing emails, counterfeit app stores, and malicious links shared on messaging apps.
  • Execution: A malicious binary (APK for Android or a payload for iOS) is installed by the victim. The malware then establishes persistent access and communicates with a web-based dashboard.

Campaign Analysis

ZeroDayRAT represents the continued commercialization of sophisticated, nation-state-level surveillance tools for a broader criminal audience. Its cross-platform capability to steal banking credentials, intercept 2FA codes, and deploy keyloggers poses a significant financial and privacy threat to mobile users.

Targeting & Infrastructure

  • Target Profile: Users of Android (version 5 through 16) and iOS devices.
  • Infrastructure: The spyware kit is advertised and sold on Telegram, with operators setting up their own self-hosted command-and-control panels.

Relevant Terms

  • Spyware: Malicious software designed to secretly observe a person's or organization's computer activities, gathering sensitive information.
  • RAT (Remote Access Trojan): A type of malware that provides an attacker with full remote administrative control over an infected computer or device.

Hackers Exploit SolarWinds For Remote Access

Executive Summary

Threat actors are actively exploiting critical vulnerabilities in SolarWinds Web Help Desk (WHD) to gain initial access and deploy legitimate tools. Attackers are using the Velociraptor digital forensics tool for command and control, persistence, and remote access on compromised systems.

Key TTPs

  • Initial Access: Exploitation of unauthenticated remote code execution vulnerabilities (CVE-2025-40551, CVE-2025-26399) in public-facing WHD instances.
  • Execution: Attackers use PowerShell to download and install legitimate Remote Monitoring and Management (RMM) tools like Zoho Assist and the Velociraptor forensics tool.
  • Defense Evasion: Malicious activity is masked by using legitimate and trusted software (Velociraptor, Zoho) for command and control. Attackers also disable Windows Defender via registry modifications.

Campaign Analysis

This campaign demonstrates a tactical shift where attackers abuse trusted incident response and administrative tools to evade detection and maintain control. Attackers deploy an outdated version of Velociraptor (0.73.4) specifically to exploit an embedded vulnerability (CVE-2025-6264). This "Bring Your Own Vulnerable Tool" technique allows them to escalate privileges from the SolarWinds service user to SYSTEM/Administrator.

Actionable Intelligence

  • Domains: auth.qgtxtebl.workers[.]dev, v2-api.mooo[.]com

Relevant Terms

  • DFIR Tool: (Digital Forensics and Incident Response) Software used by security professionals to investigate security incidents, collect forensic data, and respond to breaches.
  • Command and Control (C2): The infrastructure (servers and software) used by attackers to send commands to and receive data from a compromised system.

AI Social Network Exposes Major Risks

Executive Summary

An investigation into Moltbook, a social network for AI agents, reveals it is not a hub for advanced bot-to-bot conversation but a high-risk environment rife with security flaws, spam, and scams. A major vulnerability exposed sensitive data, including API keys and user emails.

Key Findings

  • A database misconfiguration exposed approximately 1.5 million API authentication tokens and over 35,000 user email addresses. Research indicates an 88:1 bot-to-human ratio (only ~17,000 human owners), highlighting a "Dead Internet" risk where compromised agents can be mass-weaponized.
  • The platform is vulnerable to prompt injection attacks, allowing malicious actors to trick agents into executing destructive commands or exfiltrating data.
  • Instead of intelligent discourse, the network is dominated by crypto scams, spam, and malicious actors distributing Trojans via fake software extensions.

The Bottom Line

The emergence of platforms like Moltbook highlights a critical new attack surface where autonomous AI agents can be compromised at scale. This incident demonstrates that novel AI-centric environments are being rapidly exploited, moving from theoretical playgrounds to active threat landscapes. Security leaders must prioritize developing governance and threat models for agentic AI systems, as traditional security tools are ill-equipped to monitor or prevent data exfiltration from these trusted, internally-operating agents.

Relevant Terms

  • AI Agent: An autonomous program that can perceive its environment and take actions to achieve specific goals, often capable of using tools like browsers or email.
  • Prompt Injection: A security vulnerability where an attacker crafts malicious input to manipulate an AI model's behavior, causing it to perform unintended actions.
Source: Tenable