Digital shields failing against new malware, zero-days, and data breaches.

Daily Cybersecurity News - February 14, 2026

Indian Pharmacy Giant Exposes Customer Data

Executive Summary

A major Indian pharmacy chain, DavaIndia, inadvertently exposed sensitive customer data and internal administrative controls due to a backend flaw in its web dashboards. The vulnerability, discovered by a security researcher, allowed potential access to thousands of online orders.

Attack Overview

  • Attack Path: Insecure "super admin" application programming interfaces (APIs) allowed unauthenticated access to backend systems, potentially enabling the creation of privileged accounts.
  • Attacker: The vulnerability was discovered and reported by independent security researcher "Zveare".

Impact Assessment

  • Data Exposed: Nearly 17,000 online orders were potentially accessible, including customer PII and drug purchase history.
  • Critical Risk: The flaw also allowed unauthorized users to toggle "Prescription Required" status for drugs, creating a significant public safety and regulatory liability.

Strategic Takeaway

This incident highlights the critical need for robust security controls on administrative interfaces, as a single misconfiguration can lead to widespread data exposure.

Relevant professional terms

Backend
The part of a software application that is not visible to the user, handling server-side operations, logic, and data management.
API (Application Programming Interface)
A set of rules and protocols that allows different software applications to communicate with each other.
Source: TechCrunch

Executive Summary

A newly identified threat actor, UAT-9921, is deploying a modular malware framework named VoidLink against technology and financial service sectors. Active since at least 2019, the group uses the sophisticated, Linux-focused VoidLink for long-term stealth access and reconnaissance.

Key TTPs

  • Initial Access: Use of stolen credentials or exploitation of Java serialization vulnerabilities like Apache Dubbo.
  • Execution: Deploys the VoidLink implant for command-and-control (C2) and to launch internal and external network scanning.
  • Defense Evasion: Employs kernel-level rootkits using eBPF or loadable kernel modules (LKM) to hide its activity.

Campaign Analysis

VoidLink is a polyglot framework written in Zig, a language chosen for its ability to cross-compile for Windows, Linux, and MIPS while defying standard reverse-engineering tools. This choice allows a single codebase to target diverse environments - from cloud containers to IoT edge devices, with high stealth.

Targeting & Infrastructure

  • Target Profile: Primarily technology and financial services firms, though broad network scanning suggests some opportunistic targeting.
  • Infrastructure: Uses compromised servers to host its command-and-control (C2) infrastructure and launches scans via SOCKS proxies.

Relevant Terms

  • Modular Framework: A type of malware designed with interchangeable components (modules), allowing an attacker to customize its capabilities for a specific target.
  • eBPF Rootkit: A stealth technique that uses the Extended Berkeley Packet Filter (eBPF) in the Linux kernel to hide malicious activities from security tools.

Malicious Extensions Compromise Millions

Executive Summary

A widespread campaign involving over 300 malicious Chrome extensions with more than 37 million downloads has been uncovered. These extensions are designed to steal sensitive user data, including credentials and session cookies, by tracking browsing activity and exfiltrating information.

Key TTPs

  • Initial Access: Users are tricked into installing extensions from the official Chrome Web Store, often disguised as legitimate tools like AI assistants or VPNs.
  • Execution: Malicious code injects ads, redirects traffic to phishing sites, or silently captures data as the user browses. Some extensions use remote configuration to receive new instructions without updating.
  • Defense Evasion: Attackers push malicious updates to already-popular extensions or use obfuscation and delayed execution to bypass automated scanning.

Campaign Analysis

This campaign highlights the significant threat posed by malicious browser extensions, which exploit user trust in official marketplaces. The large scale of downloads indicates a successful distribution strategy that leverages social engineering and abuse of the extension update process.

Targeting & Infrastructure

  • Target Profile: General users of the Google Chrome browser across various sectors.
  • Infrastructure: The campaign leverages the Google Chrome Web Store for distribution, with malicious code communicating with attacker-controlled command-and-control (C2) servers.

Relevant Terms

  • Session Cookies: Small pieces of data a website stores on a user's browser to remember them and keep them logged in. Stealing these can allow an attacker to hijack an active session.
  • Data Exfiltration: The unauthorized transfer of data from a computer or server. In this context, it refers to the extension sending stolen user information to an attacker.
Source: SecurityWeek

Nation-States Weaponize Zero-Days Against Defense Sector

Executive Summary

Nation-state actors from China, Russia, and Iran are aggressively targeting the Defense Industrial Base (DIB). These groups exploit zero-day vulnerabilities in network edge devices to gain initial access and maintain long-term persistence within contractor networks.

Key TTPs

  • Initial Access: Exploiting zero-day vulnerabilities in public-facing edge devices, such as VPNs and security appliances, that often lack robust monitoring.

Campaign Analysis

The high-volume use of valuable zero-day exploits signifies a strategic shift towards pre-positioning within critical networks for future intelligence gathering. This tactic allows threat actors to establish stealthy, long-term footholds that can go undetected for extended periods.

Targeting & Infrastructure

  • Target Profile: Defense Industrial Base (DIB) contractors, including aerospace, technology, and manufacturing firms supporting military capabilities.
  • Infrastructure: Network edge devices and appliances, including VPNs, routers, and firewalls from various vendors.

Relevant Terms

  • Zero-Day: A software vulnerability that is discovered by attackers before the vendor has become aware of it or has been able to release a patch.
  • Edge Devices: Hardware, such as routers, firewalls, and VPN concentrators, that sits at the boundary of a corporate network and the internet.
Source: Dark Reading

AI Artifacts Fuel macOS Infostealer Attacks

Executive Summary

Threat actors are abusing public content generated by Anthropic's Claude LLM, promoted via Google Ads, to deliver infostealer malware to macOS users. This "ClickFix" campaign tricks users searching for technical help into executing malicious commands that install the MacSync infostealer.

Key TTPs

  • Initial Access: Malicious Google search ads redirect users to fraudulent help guides hosted on public Claude artifact pages or impersonated Apple Support articles.
  • Execution: Victims are socially engineered to copy and paste a malicious one-line shell command into their macOS Terminal, which downloads and executes the malware payload.
  • Defense Evasion: The malware loader leverages native macOS attribute utilities to remove "Quarantine" flags, effectively bypassing Gatekeeper security checks.

Campaign Analysis

This campaign represents a tactical evolution, weaponizing legitimate AI-generated content on trusted domains to increase the lure's credibility. The abuse of LLM artifacts from platforms like Claude and ChatGPT for malware delivery is a growing trend in social engineering attacks.

Targeting & Infrastructure

  • Target Profile: macOS users searching for technical solutions related to topics like DNS resolving, disk space analysis, or HomeBrew.
  • Infrastructure: Google Ads, public pages on `claude.ai`, and malicious domains like `raxelpak[.]com` are used to host and deliver payloads.

Relevant Terms

  • Infostealer: A type of malware designed to covertly gather sensitive information from a victim's computer, such as passwords, browser data, and cryptocurrency wallet files.
  • ClickFix Attack: A social engineering technique that tricks users into executing malicious commands, often copied from a webpage and pasted into a command-line interface like Terminal, under the guise of fixing a technical problem.

Meta Glasses Gain Facial Recognition

Executive Summary

Meta is reportedly planning to integrate a facial recognition feature, internally codenamed "Name Tag," into its Ray-Ban smart glasses. This capability would allow the wearer's AI assistant to identify individuals and provide information about them in real-time.

Key Findings

  • The "Name Tag" feature aims to identify people a user knows through Meta's platforms or individuals with a public profile on sites like Instagram.
  • Meta's partner, EssilorLuxottica, sold over seven million units of the smart glasses in 2025, creating a large potential user base for this technology.
  • An internal memo reportedly suggested launching during a "dynamic political environment" when civil society groups might be focused on other concerns.

The Bottom Line

The integration of facial recognition into smart glasses represents a significant escalation in ambient data collection, moving digital identity tracking into the physical world. This creates a persistent surveillance capability that could be abused by threat actors for stalking or harassment and poses a uniquely dire threat to personal anonymity in public spaces. For technical leaders, this development normalizes mass data capture, creating new attack surfaces and profound ethical and data governance challenges.

Relevant Terms

  • Facial Recognition: A type of biometric technology that identifies or verifies a person from a digital image or video frame by analyzing and comparing patterns based on their facial details.
  • Biometric Data: Personal information based on unique physical or behavioral characteristics, such as fingerprints, voiceprints, or facial features, used for identification.
Source: TechCrunch

Malicious Drivers Disable Endpoint Security

Executive Summary

Threat actors are increasingly using a technique called "Bring Your Own Vulnerable Driver" (BYOVD) to gain kernel-level access on Windows systems. This allows them to terminate endpoint security products before deploying ransomware and other malware.

Key Findings

  • Attackers exploit legitimate, signed drivers with known flaws to gain the highest level of system privileges.
  • This technique is effective at disabling a wide range of EDR, AV, and XDR security solutions, rendering them blind to the subsequent attack.
  • Microsoft's primary defense, a "Vulnerable Driver Blocklist," is criticized for being reactive and having significant gaps, allowing even drivers with certificates revoked over a decade ago to be used.

The Bottom Line

The rise of BYOVD attacks represents a fundamental threat to enterprise security posture. It undermines the trust model of the operating system and demonstrates that even robust endpoint detection and response tools can be neutralized. This forces a strategic shift beyond simple EDR reliance towards proactive measures like stringent application control, driver blocklisting, and enhanced monitoring for the initial administrative access required to load these drivers.

Relevant Terms

  • BYOVD (Bring Your Own Vulnerable Driver): An attack method where threat actors place a legitimate, signed driver with known vulnerabilities onto a target system to gain kernel-level privileges.
  • Endpoint Security: Refers to the practice of securing endpoint devices like desktops and laptops. Solutions include antivirus (AV) and Endpoint Detection and Response (EDR) tools, which are the primary targets of BYOVD attacks.
Source: Dark Reading