February 2026 security reporting highlighted both macro-level incident trends and a set of high-risk, actively exploited vulnerabilities requiring rapid remediation. Hackmageddon’s February 2026 cyberattacks statistics roundup reported a threat landscape dominated by malware (33%), followed by ransomware (20%) and account takeovers (8%), based on a curated set of publicly reported events.
Recorded Future’s Insikt Group reported a 43% month-over-month decrease in “high-impact” vulnerabilities (13 in February vs. 23 in January), but emphasized that all 13 carried a Very Critical risk score and were actively exploited. The report noted Microsoft accounted for 6 of 13 vulnerabilities (and that these were added to CISA KEV the same day), described a suspected China-nexus Lotus Blossom supply-chain compromise of Notepad++ updates via CVE-2025-15556 to deliver Cobalt Strike and the Chrysalis backdoor, and stated APT28 exploited an MSHTML flaw (CVE-2026-21513) using malicious Windows Shortcut files; it also flagged that multiple issues had public proof-of-concept exploits and referenced a critical BeyondTrust Remote Support OS command injection affecting versions 25.3.1 and earlier.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
On March 12, 2026, Recorded Future's Insikt Group published a report on the February 2026 CVE landscape. The report emphasized that although the number of actively exploited high-impact flaws fell from January, the month's vulnerabilities remained highly dangerous.
On March 12, 2026, Hackmageddon published its February 2026 cyber attack statistics page, summarizing the month's attack trends and linking to the first- and second-half February timelines. The fragment also contextualized the data with prior monthly statistics posts.
Recorded Future reported that UNC6201 exploited CVE-2026-22769 affecting Dell RecoverPoint for VMs in February 2026. The case was included among the month's actively exploited, high-impact vulnerabilities requiring immediate remediation.
Recorded Future identified APT28 as exploiting CVE-2026-21513 through malicious .lnk files during February 2026. The activity was cited as one of the month's notable examples of named threat actor exploitation.
Recorded Future highlighted Lotus Blossom's supply-chain compromise of Notepad++ through CVE-2025-15556. Attackers abused the WinGUp update mechanism to deliver Cobalt Strike Beacon and the Chrysalis backdoor, prompting urgent upgrade and threat-hunting guidance.
Recorded Future reported that 13 actively exploited high-impact vulnerabilities were identified in February 2026, down 43% from 23 in January. Despite the lower count, all 13 were rated 'Very Critical' and included five flaws enabling remote code execution.
A referenced Hackmageddon timeline for 1-15 February 2026 stated that 96 cyber attack events were collected during the first half of the month. Malware was identified as the dominant threat category in that period.
Hackmageddon's January 2026 statistics post reported that 178 cyber attack events were collected and analyzed for the month. The post said cyber crime was the leading motivation among those incidents.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.