This cybersecurity brief for February 25, 2026, covers several major incidents. Google and Mandiant announced the disruption of a sprawling Chinese espionage campaign by UNC2814, which used a novel backdoor called GRIDTIDE that abused Google Sheets for command and control. In a significant tactical shift, North Korea's Lazarus Group was observed deploying Medusa ransomware in attacks on healthcare. Data extortion group ShinyHunters was linked to two massive breaches, leaking 12.4 million records from CarGurus and stealing data from 800,000 Wynn Resorts employees. Meanwhile, CISA added actively exploited vulnerabilities in Cisco and Soliton products to its KEV catalog, mandating urgent patching. These events highlight the increasing sophistication of state-sponsored threats, the industrialization of cybercrime, and the critical need for robust vulnerability management.
Help others stay informed about cybersecurity threats