Daily Digest

Google Disrupts Global Chinese Spy Campaign; Lazarus Group Adopts Medusa Ransomware; Massive Data Breaches Rock Corporations

Google Disrupts Global Chinese Spy Campaign; Lazarus Group Adopts Medusa Ransomware; Massive Data Breaches Rock Corporations

February 25, 2026
11 articles (10 new, 1 updated)
33 min read

Summary

This cybersecurity brief for February 25, 2026, covers several major incidents. Google and Mandiant announced the disruption of a sprawling Chinese espionage campaign by UNC2814, which used a novel backdoor called GRIDTIDE that abused Google Sheets for command and control. In a significant tactical shift, North Korea's Lazarus Group was observed deploying Medusa ransomware in attacks on healthcare. Data extortion group ShinyHunters was linked to two massive breaches, leaking 12.4 million records from CarGurus and stealing data from 800,000 Wynn Resorts employees. Meanwhile, CISA added actively exploited vulnerabilities in Cisco and Soliton products to its KEV catalog, mandating urgent patching. These events highlight the increasing sophistication of state-sponsored threats, the industrialization of cybercrime, and the critical need for robust vulnerability management.

Filter by Category

New Articles (10)

Updated Articles (1)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.