The referenced items are weekly newsletter/roundup posts that aggregate multiple, unrelated cybersecurity developments rather than reporting a single discrete incident. They highlight a mix of data breaches, ransomware, active exploitation and KEV additions, and malware campaigns—including mentions of BeyondTrust RS/PRA vulnerabilities (including CVE-2026-1731) being exploited, CISA adding various flaws to the Known Exploited Vulnerabilities (KEV) catalog, and ongoing malware activity such as LummaStealer, NetSupport RAT targeting, and Linux botnet activity (e.g., SSHStalker).
Separately, the roundup coverage also includes public-sector and critical-service disruptions and regulatory action: a reported cyberattack on the European Commission’s mobile device management (MDM) environment with potential exposure of staff contact details, a ransomware incident disrupting Senegal’s national identity services, and an Australian court penalty against FIIG Securities tied to inadequate cybersecurity controls following a prior ransomware breach and data exposure. Overall, the content is best treated as situational awareness across many stories, not as a cohesive incident requiring a single-issue response plan.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
India introduced formal rules for labeling and handling AI-generated content, with the measures becoming effective on 2026-02-20. The policy was highlighted as a notable regulatory development in the roundup.
On 2026-02-15, Security Affairs published Malware Newsletter Round 84, aggregating reporting on campaigns and malware including NetSupport RAT activity, ZeroDayRAT, SSHStalker, AgreeToSteal, LummaStealer, CastleLoader, BADIIS, and VoidLink-linked operations. The piece compiled previously reported technical developments rather than announcing one discrete incident.
On 2026-02-15, Security Affairs' weekly international newsletter summarized ongoing exploitation of multiple vulnerabilities, recent vendor patches, and breach disclosures affecting organizations including Odido, ApolloMD, Conduent/Volvo Group, Figure, Flickr, and Senegal’s national ID-related office. The item was a roundup rather than a single newly reported incident.
In the United States, Daren Li was sentenced in absentia to 20 years in prison for a $73 million cryptocurrency pig-butchering fraud scheme. The case involved laundering nearly $60 million through U.S. shell companies.
Australian authorities imposed a landmark AU$2.5 million penalty on FIIG Securities, plus AU$500,000 in legal costs, over inadequate cybersecurity controls. The action was tied to control failures that preceded a 2023 ransomware breach exposing 385GB of client data.
Senegal’s Directorate of File Automation suffered a ransomware attack that halted identity card production and disrupted national ID, passport, and electoral services. Authorities said personal data was not compromised and the investigation remained ongoing.
The European Commission said the January 30 intrusion was contained within nine hours of detection. Its disclosure indicated the impact was limited to data exposure involving staff contact details.
On 2026-01-30, the European Commission disclosed a cyberattack affecting its mobile device management system. The incident may have exposed staff names and mobile phone numbers, but officials said no devices were compromised.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcesecurityaffairs.com
Open sourcethecyberexpress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.