Reporting during the week of Feb. 23 highlighted multiple unrelated security incidents and research findings rather than a single cohesive event. France’s Ministry of Economy disclosed unauthorized access to the national bank account registry FICOBA, exposing data tied to ~1.2 million accounts (e.g., names, addresses, account identifiers, and in some cases tax-related identifiers), with officials attributing access to compromised government credentials. Separately, Advantest reported a ransomware intrusion following third-party unauthorized access, University of Mississippi Medical Center experienced a ransomware event that disrupted clinics and electronic medical records, and Ukraine’s National Bank reported a supply-chain exposure at a contractor supporting its collectible coin online store (customer registration data exposed; payment data reportedly unaffected). In Taiwan, Taipei Grand Hotel said a third party accessed internal systems without authorization during the Lunar New Year period; the hotel took networks offline for forensics and warned customers to be cautious of suspicious messages.
Threat-actor and technique reporting also described ongoing campaigns and emerging tradecraft. MuddyWater (Iran-aligned) was reported targeting MENA organizations in “Operation Olalampo,” using phishing lures with malicious Office documents/macros to deploy tooling including GhostFetch, HTTP_VIP, a Rust backdoor CHAR, and an implant dubbed GhostBackDoor, with one chain also deploying AnyDesk for remote access. Separately, reporting on DPRK-linked crypto operations described sustained, social-engineering-led targeting of the crypto ecosystem following the Bybit theft, including AI-assisted persona and communication crafting and laundering via mixing/OTC pathways. Additional research noted internet-wide scanning telemetry involving OAST/Interactsh callback domains and shifts toward cookie-based injection, while another item profiled PRC-attributed Lotus Blossom as an espionage actor (including discussion of the Notepad++ ecosystem incident) and a separate post provided general reconnaissance methodology rather than incident-specific intelligence.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
22 events from the most recent confirmed update back to the earliest known activity.
Sherpa Intelligence reported that ShinyHunters allegedly stole more than 800,000 Wynn records and demanded $1.5 million to prevent the data from being leaked.
Check Point reported that Chrome zero-day CVE-2026-2441 was being exploited in the wild, marking a notable active exploitation event.
Check Point's bulletin highlighted critical Grandstream VoIP remote code execution flaw CVE-2026-2329 as a significant newly reported vulnerability.
Check Point summarized a supply-chain campaign in which an npm worm spread via typosquatting, stole developer and CI secrets, and targeted AI coding assistants to harvest LLM API keys.
A Russian-speaking actor was reported using commercial generative AI to scale credential abuse against FortiGate devices and then pivot to target Veeam servers.
Check Point researchers demonstrated that AI assistants such as Grok and Microsoft Copilot can be misused as covert command-and-control channels, highlighting a new AI-enabled threat technique.
Check Point reported a supply-chain exposure at a contractor supporting the National Bank of Ukraine's collectible coin store, leaking customer registration data but not payment information.
Advantest disclosed that an unauthorized party accessed parts of its network and that the incident involved ransomware, according to the Check Point bulletin and Sherpa roundup.
French authorities disclosed that attackers used stolen credentials to access the FICOBA national bank-account registry and exfiltrated data tied to 1.2 million accounts.
Taiwan News published reporting that Taipei Grand Hotel had been targeted in a cyberattack, indicating a newly disclosed victim in Taiwan's hospitality sector.
On February 19, 2026, the University of Mississippi Medical Center detected a ransomware attack that disrupted network and IT systems, including its Epic electronic medical record environment.
Between February 14 and February 20, 2026, GreyNoise recorded 5,695 OAST domain occurrences across 3,882 sessions from 24 source IPs, with increased cookie-based injection and heavy Nuclei/loopback usage.
Group-IB said a new MuddyWater campaign dubbed Operation Olalampo was first observed on January 26, 2026, targeting organizations and individuals across the Middle East and North Africa with phishing and malware delivery.
From January 1 to mid-February 2026, the DangerousPassword and Contagious Interview campaigns allegedly generated $37.5 million by tricking victims into installing malware that steals keys, seed phrases, and credentials.
The reporting states that DPRK-linked operators stole a record $2 billion in 2025, bringing cumulative known cryptocurrency thefts attributed to North Korea to more than $6 billion.
On December 8, 2025, the Cheyenne and Arapaho Tribes experienced an intrusion that disrupted schools and government operations; Rhysida later claimed responsibility according to the roundup.
Sherpa Intelligence reported that the ShinyHunters-linked breach of Wynn involved initial access in September 2025 through an Oracle PeopleSoft vulnerability and an employee's credentials.
On February 21, 2025, North Korea-linked operators allegedly stole about $1.46 billion in cryptoassets from Dubai-based exchange Bybit, in what the report describes as the largest confirmed crypto theft to date.
The group allegedly began a 2025-2026 supply-chain campaign targeting Notepad++ by manipulating update infrastructure to distribute trojanized updater components and deliver the Chrysalis backdoor via DLL sideloading.
In 2022, Lotus Blossom reportedly escalated from traditional intrusion methods to compromising a national certificate authority, marking a shift toward attacks on mechanisms of trust.
Check Point reported that suspected Chinese threat actor UNC6201 has exploited Dell RecoverPoint for VMs zero-day CVE-2026-22769 since mid-2024, indicating a prolonged real-world exploitation window before public reporting.
Lotus Blossom is described as an APT active since at least 2009, conducting cyber-espionage operations primarily against government, military, and strategic-sector targets in the Asia-Pacific region.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
research.checkpoint.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcesherpaintelligence.substack.com
Open sourcelabs.greynoise.io
Open sourcetaiwannews.com.tw
Open sourcesocradar.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.