LogoSignal
Intelligence Dispatch
Subscribe
CVE-2026-0847 · CVSS 9.8 · RCE in OpenSSH 9.6APT41 · NEW CAMPAIGN · Financial Sector TargetingZERO-DAY · Chrome V8 · Patch AvailableRANSOMWARE · LockBit 4.0 · Healthcare SectorADVISORY · CISA KEV · 3 New Entries TodayEXPLOIT · PoC Published · Ivanti Connect SecureCVE-2026-0847 · CVSS 9.8 · RCE in OpenSSH 9.6APT41 · NEW CAMPAIGN · Financial Sector TargetingZERO-DAY · Chrome V8 · Patch AvailableRANSOMWARE · LockBit 4.0 · Healthcare SectorADVISORY · CISA KEV · 3 New Entries TodayEXPLOIT · PoC Published · Ivanti Connect Secure

THURSDAY · THURSDAY, FEBRUARY 26, 2026 · VOL. IV · ISSUE 38

THE THREAT LANDSCAPE MOVED OVERNIGHT.

DAILY INTELLIGENCE DISPATCH FOR SECURITY PROFESSIONALS

SCROLL TO READ TODAY'S BRIEF

PANEL 01 / TODAY'S BRIEF

Top Threats, 26 Feb 2026

CRITICALCVSS 9.8

CVE-2026-0847

OpenSSH 9.6 / Remote Code Execution

An unauthenticated heap overflow in the OpenSSH daemon allows a remote attacker to achieve arbitrary code execution as root on affected Linux systems. Exploitation has been confirmed in the wild; CISA added to KEV this morning at 04:12 EST.

RCELinuxNetwork PerimeterKEV
NVD · CISA · Qualys TRU04:12 EST

14.2M exposed instances (Shodan)

HIGHCVSS 8.1

CVE-2026-1203

Ivanti Connect Secure — Auth Bypass

A logic flaw in the SAML assertion validation pipeline permits an unauthenticated actor to impersonate any VPN user. A functional PoC was published on GitHub at 01:30 UTC. Ivanti has released a hotfix; patch velocity is the current concern.

Auth BypassVPNPoC AvailableSAML
Ivanti PSIRT · Rapid7 AttackerKB01:30 UTC

~9,400 unpatched gateways

MEDIUMCVSS 6.5

CVE-2026-0991

Chrome V8 Engine — Type Confusion

A type confusion vulnerability in the V8 JavaScript engine can be triggered by visiting a malicious web page. Google released Chrome 122.0.6261.94 overnight. No confirmed in-the-wild exploitation, though the bug class historically escalates quickly.

BrowserV8Type ConfusionPatch Ready
Google Project Zero · Chrome Release Blog23:44 UTC

All Chrome < 122.0.6261.94

CONTINUE TO DEEP READ

PANEL 02 / DEEP READ

Feature Analysis

Abstract visualization of network threat data with dark background and glowing connection nodes

Analysis by the Signal Research Desk. Sources: Mandiant Threat Intelligence, CrowdStrike Adversary Intelligence, MITRE ATT&CK Framework v14.

PUBLISHED 26 FEB 2026 · 05:30 EST

KEY INDICATORS

Threat ActorAPT41 (BARIUM / Winnti)
Campaign StartJanuary 14, 2026
Sectors TargetedFinance, Insurance, Healthcare
TTPsT1190, T1566.001, T1071.001
ConfidenceHIGH — Corroborated by 4 Sources

APT41's Return: How China's Most Versatile Threat Group Pivoted to Financial Infrastructure in Q1 2026

Since early January, Mandiant's threat intelligence teams have tracked a resurgence in APT41 activity targeting SWIFT-connected financial institutions across North America and Southeast Asia. The group, historically known for dual espionage and financially motivated operations, appears to have shifted its primary toolset — moving away from its signature POISONPLUG implant toward a new loader family internally designated as SILKTHREAD.

Initial access vectors in confirmed intrusions share a common pattern: a weaponized PDF delivered via spear-phishing, exploiting CVE-2025-4891 in Adobe Acrobat Reader. Once inside, the actor demonstrates exceptional operational security — living off the land with WMI subscriptions and scheduled tasks, avoiding the kind of noisy lateral movement that triggers modern EDR solutions.

"The pivot to financial infrastructure isn't opportunistic — it's a deliberate strategic escalation. This group now has the capability to disrupt clearing operations, not just exfiltrate data."

— SENIOR THREAT ANALYST, MANDIANT (IDENTITY WITHHELD)

Detection opportunities remain narrow but actionable. Security teams should prioritize hunting for anomalous WMI subscriptions with base64-encoded payloads, unexpected outbound connections to ASN 45102 (Alibaba Cloud), and the specific registry key persistence mechanism documented in the SILKTHREAD YARA signatures published by CrowdStrike at 03:00 UTC this morning.

PANEL 03 / WEEKLY TRENDS

Exploit Volume, 8-Week View

453423110
Jan 6
Jan 13
Jan 20
Jan 27▲
Feb 3
Feb 10
Feb 17▲
Feb 24▲

▲ DENOTES CRITICAL SPIKE WEEKS · SOURCE: NVD, EXPLOIT-DB, CISA KEV · DATA AS OF 25 FEB 2026

SAMPLE ISSUE · FEB 19, 2026

What you get, every morning at 06:00 EST.

No marketing. No filler. Exactly what changed in the threat landscape overnight — formatted for the first 10 minutes of your shift.

◈

CVE Digest

3–5 critical/high items, CVSS scored

◉

Threat Actor Brief

Active campaigns, new TTPs, attribution

◆

Exploit Watch

PoCs, weaponized modules, KEV updates

◇

Tool Drops

New offensive/defensive tooling released

○

Patch Velocity

What's unpatched 7+ days post-advisory

READ THIS WEEK'S ARCHIVE →

PANEL 04 / TOOLS & SUBSCRIBE

Curated Resources

Offensive

Sliver C2 v1.5.43

NEW RELEASE

New implant evasion techniques in latest release. OPSEC improvements for memory-only payloads.

github.com/BishopFox/sliver →

Nuclei Templates

UPDATED

47 new templates added for CVE-2026-0847 and related OpenSSH detection.

github.com/projectdiscovery →

Defensive

Velociraptor 0.7.1

NEW RELEASE

DFIR platform release adds SILKTHREAD artifact collection pack for APT41 hunting.

docs.velociraptor.app →

Sigma Rules

COMMUNITY

Community-contributed detections for the Ivanti Connect Secure auth bypass (CVE-2026-1203).

github.com/SigmaHQ/sigma →

Intelligence

MITRE ATT&CK v14.1

UPDATED

Minor update adds 3 new APT41 sub-techniques under T1071 based on Q1 2026 reporting.

attack.mitre.org →

CISA KEV Feed

ADVISORY

3 new entries added 25 Feb: CVE-2026-0847, CVE-2025-38821, CVE-2025-41190.

cisa.gov/kev →

DAILY DISPATCH · FREE

Get Tomorrow's Brief.

Delivered to your inbox at 06:00 EST. Read in 10 minutes. No vendor noise, no marketing — only what the SOC needs to know before the first standup.

◈4,200+ security professionals subscribed
◈Trusted by teams at Mandiant, CrowdStrike & SANS
◈Unsubscribe anytime — no friction
01 / 04 · THREATS