CyberNews: 14/02/2026 Edition

Published by Dunateo on 2026-02-14

Today’s roundup

  • New threat actor UAT-9921 deploys VoidLink against enterprise sectors
  • Nation-State Hackers Put Defense Industrial Base Under Siege
  • Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs
  • Fake job recruiters hide malware in developer coding challenges
  • EU can’t be ‘naive’ about enemies shutting down critical infrastructure, warns tech official
  • NATO must impose costs on Russia, China over cyber and hybrid attacks, says deputy chief
  • China may be rehearsing a digital siege, Taiwan warns
  • Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches
  • Space emerges as new front in great power competition, officials warn
  • Ring ends partnership plans with Flock days after privacy blowback from Super Bowl ad
  • Summary

    A new threat actor, UAT-9921, is deploying the sophisticated modular attack framework VoidLink to target technology and financial organizations. Identified by Cisco Talos, VoidLink is described as "defense-contractor grade" and leverages AI-enabled coding tools for its development. Active since at least 2019, the Linux-focused framework includes advanced capabilities such as eBPF/LKM rootkits, container escape, privilege escalation, cloud awareness, EDR evasion, and a mesh peer-to-peer design.

    Espionage groups, including those from China and Russia, are actively targeting the defense industrial base (DIB), utilizing at least two dozen zero-day vulnerabilities in edge devices to infiltrate defense contractors' networks. This highlights a significant and ongoing threat to critical national security infrastructure.

    Google Threat Intelligence Group (GTIG) has linked a suspected Russian actor, possibly affiliated with Russian intelligence, to attacks deploying new malware dubbed CANFAIL. These attacks are targeting defense, military, government, and energy organizations within Ukraine, indicating a continued focus on disrupting critical sectors.

    North Korean threat actors are employing a new variation of their fake recruiter campaign, specifically targeting JavaScript and Python developers. The malicious campaigns hide malware within coding challenges related to cryptocurrency tasks, aiming to compromise victim systems.

    A top European Union tech official has issued a warning against being "naive" about adversaries' capabilities to disrupt critical infrastructure through cyber and hybrid threats. The official called for tougher regulations and increased investment to fortify Europe's defenses.

    NATO's Deputy Secretary General, Radmila Shekerinska, stated at the Munich Cyber Security Conference that NATO must impose costs on Russia and China for their cyber and hybrid attacks. She emphasized the increasingly complex and contested global security environment.

    Taiwan has issued a stark warning regarding China's intentions to utilize cyberspace for new and more aggressive strategies, including potentially rehearsing a "digital siege." This alert comes amid growing concerns about regional cyber warfare capabilities.

    South Korea has imposed a $25 million fine on luxury fashion brands Louis Vuitton, Christian Dior Couture, and Tiffany. The penalty was levied due to their failure to implement adequate security measures, which led to unauthorized access and the exposure of data belonging to over 5.5 million customers.

    Officials have warned that space is emerging as a new front in great power competition. The domain, crowded with satellites, is considered vulnerable to disruption, and current international rules are deemed inadequate for the complex challenges presented.

    Ring has terminated its partnership plans with Flock Safety following significant public and privacy blowback from a Super Bowl advertisement. The controversy arose from the proposed ability for Ring customers to share their doorbell camera videos directly with police through Ring’s Community Requests program.

    Want to dig deeper?

    Malware Families

    Global GLOBAL GROUP