This cybersecurity brief for February 22-23, 2026, covers a wave of critical threats. Atlassian and Microsoft rushed patches for actively exploited zero-days in Confluence (CVE-2026-22515) and a critical flaw in Exchange Server (CVE-2026-21445). A new ransomware strain, "MidasTouch," crippled a major US hospital chain, while CISA warned of the "SandViper" APT targeting the defense sector. Other major incidents include a supply chain attack on the "EasyUtil-JS" NPM package and a massive data breach at payment processor "GlobalPay" exposing 20 million credit cards.
Help others stay informed about cybersecurity threats