State-Backed Hackers Weaponize AI, Microsoft Patches Six Zero-Days, and Conduent Breach Exceeds 25 Million Victims

Publication Date: February 14, 2026

Summary

In the last 24 hours, the cybersecurity landscape has been defined by a confluence of advanced persistent threats, critical vulnerability management, and the escalating consequences of massive data breaches. A landmark report from Google confirmed that state-sponsored actors from China, Russia, Iran, and North Korea are actively weaponizing large language models like Gemini to enhance their cyber operations. Concurrently, Microsoft released its February Patch Tuesday, addressing 58 flaws, including six zero-days under active exploitation. The fallout from past incidents continues, as the 2025 Conduent data breach victim count swelled to over 25 million, prompting a major investigation. In response to rising threats, government agencies are taking action, with CISA mandating the removal of end-of-life devices and the UK's NCSC issuing a severe warning to critical infrastructure operators.

Today New Articles

Nation-State Hackers from China, Russia, and Iran Weaponize Google's Gemini AI for Attacks

A new report from Google's Threat Intelligence Group (GTIG) confirms that state-sponsored hacking groups from China, Iran, North Korea, and Russia are systematically using large language models (LLMs), including Google's own Gemini, to augment their cyber oper...


Conduent Data Breach Victim Count Skyrockets to 25 Million, Triggering Texas AG Investigation

The fallout from the 2025 data breach at business services provider Conduent has dramatically worsened, with the number of affected individuals now estimated to be over 25 million, a significant jump from the 10.5 million initially reported. The breach involve...


Germany Prepares Legislation to Authorize Offensive Cyber Operations in Major Policy Shift

The German government is reportedly drafting legislation to formally authorize its intelligence agencies and military to conduct offensive cyber operations. This significant policy shift would move Germany from its traditionally defensive posture to one that i...


'Crazy' Ransomware Gang Abuses Legitimate Employee Monitoring Software for Stealthy Persistence

The 'Crazy' ransomware gang has been observed using a new 'living off the land' tactic, abusing legitimate commercial software to maintain stealthy and persistent access to victim networks. Researchers report the group deployed 'Net Monitor for Employees Profe...


Google Details Coordinated Cyber Espionage Campaigns Against Global Defense Industrial Base

A comprehensive report from Google's Threat Intelligence Group (GTIG) details a multi-pronged assault on the global Defense Industrial Base (DIB) by state-sponsored actors from China, Iran, North Korea, and Russia. The campaigns use diverse tactics, including...

Article Updates

Ransomware Attacks Skyrocket 58% in 2025, Setting New Records

Update:New analyses from Cyble and BlackFog reveal 2025 ransomware attacks surged by 52% to over 6,600 incidents. A critical development is the near-universal adoption of data exfiltration, with 96% of attacks now employing double extortion tactics. The Qilin group r...


Substack Discloses Data Breach Exposing User Contact Information

Update:The Substack data breach, initially reported on February 6, 2026, has new confirmed details. The number of affected users is now precisely stated as 697,313, moving beyond the initial hacker's claim of '700,000 users'. Crucially, the stolen database, containin...


BridgePay Payment Gateway Hit by Ransomware, Causing Nationwide Outages

Update:BridgePay Network Solutions has provided further details regarding the ransomware attack that began on February 6, 2026. The incident started at approximately 3:29 a.m. when monitoring systems detected degraded performance, quickly escalating to a full system...


Microsoft Scrambles to Fix Six Actively Exploited Zero-Days in February 2026 Patch Tuesday

Update:In addition to the February 2026 Patch Tuesday fixes, Microsoft has commenced a phased rollout of new Secure Boot certificates. These certificates are crucial for maintaining system integrity and are replacing older ones set to expire in June 2026. This proact...


Dutch Telecom Odido Suffers Massive Data Breach; 6 Million Customers Potentially Exposed

Update:Further investigation into the Odido data breach, initially reported on February 11, 2026, has clarified key details. The compromised system is now identified as a 'customer contact system' rather than broadly a 'third-party supplier's system'. Crucially, the...


CISA Warns Energy Sector of Destructive ICS/OT Attacks After Poland Grid Hit

Update:The UK's National Cyber Security Centre (NCSC) has issued a 'severe' threat warning to its Critical National Infrastructure (CNI) operators, urging immediate action against disruptive and destructive cyberattacks. This alert, dated February 14, 2026, directly...