PANEL 01 / TODAY'S BRIEF
Top Threats, 26 Feb 2026
CVE-2026-0847
OpenSSH 9.6 / Remote Code Execution
An unauthenticated heap overflow in the OpenSSH daemon allows a remote attacker to achieve arbitrary code execution as root on affected Linux systems. Exploitation has been confirmed in the wild; CISA added to KEV this morning at 04:12 EST.
14.2M exposed instances (Shodan)
CVE-2026-1203
Ivanti Connect Secure — Auth Bypass
A logic flaw in the SAML assertion validation pipeline permits an unauthenticated actor to impersonate any VPN user. A functional PoC was published on GitHub at 01:30 UTC. Ivanti has released a hotfix; patch velocity is the current concern.
~9,400 unpatched gateways
CVE-2026-0991
Chrome V8 Engine — Type Confusion
A type confusion vulnerability in the V8 JavaScript engine can be triggered by visiting a malicious web page. Google released Chrome 122.0.6261.94 overnight. No confirmed in-the-wild exploitation, though the bug class historically escalates quickly.
All Chrome < 122.0.6261.94
PANEL 02 / DEEP READ
Feature Analysis

Analysis by the Signal Research Desk. Sources: Mandiant Threat Intelligence, CrowdStrike Adversary Intelligence, MITRE ATT&CK Framework v14.
PUBLISHED 26 FEB 2026 · 05:30 EST
KEY INDICATORS
APT41's Return: How China's Most Versatile Threat Group Pivoted to Financial Infrastructure in Q1 2026
Since early January, Mandiant's threat intelligence teams have tracked a resurgence in APT41 activity targeting SWIFT-connected financial institutions across North America and Southeast Asia. The group, historically known for dual espionage and financially motivated operations, appears to have shifted its primary toolset — moving away from its signature POISONPLUG implant toward a new loader family internally designated as SILKTHREAD.
Initial access vectors in confirmed intrusions share a common pattern: a weaponized PDF delivered via spear-phishing, exploiting CVE-2025-4891 in Adobe Acrobat Reader. Once inside, the actor demonstrates exceptional operational security — living off the land with WMI subscriptions and scheduled tasks, avoiding the kind of noisy lateral movement that triggers modern EDR solutions.
"The pivot to financial infrastructure isn't opportunistic — it's a deliberate strategic escalation. This group now has the capability to disrupt clearing operations, not just exfiltrate data."
— SENIOR THREAT ANALYST, MANDIANT (IDENTITY WITHHELD)
Detection opportunities remain narrow but actionable. Security teams should prioritize hunting for anomalous WMI subscriptions with base64-encoded payloads, unexpected outbound connections to ASN 45102 (Alibaba Cloud), and the specific registry key persistence mechanism documented in the SILKTHREAD YARA signatures published by CrowdStrike at 03:00 UTC this morning.
PANEL 03 / WEEKLY TRENDS
Exploit Volume, 8-Week View
▲ DENOTES CRITICAL SPIKE WEEKS · SOURCE: NVD, EXPLOIT-DB, CISA KEV · DATA AS OF 25 FEB 2026
SAMPLE ISSUE · FEB 19, 2026
What you get, every morning at 06:00 EST.
No marketing. No filler. Exactly what changed in the threat landscape overnight — formatted for the first 10 minutes of your shift.
CVE Digest
3–5 critical/high items, CVSS scored
Threat Actor Brief
Active campaigns, new TTPs, attribution
Exploit Watch
PoCs, weaponized modules, KEV updates
Tool Drops
New offensive/defensive tooling released
Patch Velocity
What's unpatched 7+ days post-advisory
PANEL 04 / TOOLS & SUBSCRIBE
Curated Resources
Offensive
Sliver C2 v1.5.43
NEW RELEASENew implant evasion techniques in latest release. OPSEC improvements for memory-only payloads.
github.com/BishopFox/sliver →Nuclei Templates
UPDATED47 new templates added for CVE-2026-0847 and related OpenSSH detection.
github.com/projectdiscovery →Defensive
Velociraptor 0.7.1
NEW RELEASEDFIR platform release adds SILKTHREAD artifact collection pack for APT41 hunting.
docs.velociraptor.app →Sigma Rules
COMMUNITYCommunity-contributed detections for the Ivanti Connect Secure auth bypass (CVE-2026-1203).
github.com/SigmaHQ/sigma →Intelligence
MITRE ATT&CK v14.1
UPDATEDMinor update adds 3 new APT41 sub-techniques under T1071 based on Q1 2026 reporting.
attack.mitre.org →CISA KEV Feed
ADVISORY3 new entries added 25 Feb: CVE-2026-0847, CVE-2025-38821, CVE-2025-41190.
cisa.gov/kev →DAILY DISPATCH · FREE
Get Tomorrow's Brief.
Delivered to your inbox at 06:00 EST. Read in 10 minutes. No vendor noise, no marketing — only what the SOC needs to know before the first standup.