
Loading summary
Host
From the CISO series, it's Cybersecurity Headlines
Steve Prentiss
these are the cybersecurity headlines for Friday, February 20, 2026. I'm Steve Prentiss. CISA orders urgent patch of Del Flaw following up on a story we covered yesterday, CISA has now ordered government agencies to patch their systems within three days against a maximum severity Dell vulnerability that has been under active exploitation since mid 2024. This CVE numbered hard coded credential vulnerability in Dell's Recover Point, which is a solution used for VMware virtual machine backup and recovery, is being exploited by a suspected Chinese hacking group tracked as UNC6201. It is being used to deploy several malware payloads, including a backdoor called grimbolt, which uses a compilation technique that makes it harder to analyze than its predecessor, the Brickstorm backdoor. Android malware uses Gemini to navigate infected devices According to researchers at eset, the
Cybersecurity Analyst
first Android malware strain that uses generative
Steve Prentiss
AI to improve performance once installed has appeared, but this may just be a proof of concept. The goal of the malware, named PromptSpy, is to deploy a VNC module that hands hackers remote control of infected devices.
Cybersecurity Analyst
ESET says. It comes with capabilities to instruct Google's
Steve Prentiss
Gemini Chatbot to interpret parts of the device's user interface using natural language prompts, which allow the malware to examine the user interface. This then informs the gestures it needs to execute on the device in order to keep the malicious app pinned to its Recent Apps list. ESET found versions of PromptSpy uploaded to
Cybersecurity Analyst
VirusTotal in January with the Gemini assisted
Steve Prentiss
strains submitted from Argentina. Half of all cyber attacks start in the browser, says Palo Alto Networks. According to their 2026 Global Incident Response
Cybersecurity Analyst
Report, which analyzed 750 major cyber incidents across 50 countries in 2025, 48% of cybercrime events involved browser activity.
Steve Prentiss
The report identifies phishing malicious links, credential
Cybersecurity Analyst
harvesting pages, spoofed websites, and even click
Steve Prentiss
fix as browser enabled tools.
Cybersecurity Analyst
Among its 10 recommendations use a password manager and an ad blocker, switch to an anonymous search engine like DuckDuckGo and
Steve Prentiss
be wary of AI browsers. New commercial grade phishing kit bypasses MFA named Star Killer, but unrelated to the Red Team penetration testing tool of the same name.
Cybersecurity Analyst
This kit is distributed on the Dark
Steve Prentiss
Web in a software as a service model, including a subscription, updates and customer
Cybersecurity Analyst
support, whereas most other phishing kits use HTML clones of a victim's login page. Starkiller launches a phishing site through a
Steve Prentiss
proxy operated by infrastructure it controls, which
Cybersecurity Analyst
makes it indistinguishable from the real login
Steve Prentiss
portal being used as a template. Because starkiller proxies the real site live, there are no template files for security vendors to fingerprint or blocklist.
Cybersecurity Analyst
This also enables it to bypass MFA because the targeted user is authenticating with
Steve Prentiss
the real site through the proxy. End quote.
Cybersecurity Analyst
Huge thanks to our sponsor Conveyor. Most of what Conveyor automates is boring. Like really boring Security questionnaires, customer requests
Steve Prentiss
for things like your SoC2, all of their follow up questions answering tickets from your sales team. But you know what's not boring?
Cybersecurity Analyst
Alteryx using Conveyor to support over half a billion dollars in enterprise deals with a small four person team.
Steve Prentiss
All they did was set up an
Cybersecurity Analyst
AI trust center and use Conveyor's AI
Steve Prentiss
agent to complete the questionnaires.
Cybersecurity Analyst
You can learn more@conveyor.com that is conveyor.
Steve Prentiss
France's national bank account database suffers cyberattack
Cybersecurity Analyst
French authorities have confirmed that a malicious actor illegally accessed a portion of the country's national bank accounts file known as
Steve Prentiss
ficoba F I C O B A,
Cybersecurity Analyst
which records all bank accounts in the country. The bank account database consists in general of more than 80 million individuals and in this attack it is believed that
Steve Prentiss
1.2 million accounts were impacted.
Cybersecurity Analyst
It is said that the hacker impersonated a civil servant whose credentials allowed access as part of inter ministerial information exchanges
Steve Prentiss
to query part of the database.
Cybersecurity Analyst
A representative said that the file contains a list of bank account details but does not provide access to the accounts
Steve Prentiss
themselves, nor to account balances, nor to transactions.
Cybersecurity Analyst
Jackpotting on the rise due to malware
Steve Prentiss
stuffed ATMs not a new technique in
Cybersecurity Analyst
itself, but the FBI says this technique
Steve Prentiss
is on the rise across the United States.
Cybersecurity Analyst
ATM jackpotting is a technique where physical and software vulnerabilities in ATMs are exploited to deploy malware that instructs the machine
Steve Prentiss
to dispense cash on demand without bank authorization.
Cybersecurity Analyst
Plautus malware that is P L O
Steve Prentiss
U T U S which is commonly
Cybersecurity Analyst
used in these attacks, exploits extensions for financial services, which is an open standard
Steve Prentiss
API that ATMs point of sale terminals and similar devices that run banking applications use the Department of Health and Human
Cybersecurity Analyst
Services to learn more about third party vendors in healthcare. The HHS said on Thursday that this uptick in attention to the security of third party service providers is a result of the 2024 CHANGE Healthcare Cyber attack,
Steve Prentiss
considered the biggest ever in the sector.
Cybersecurity Analyst
The Change Healthcare attack began with hackers exploiting the lack of multi factor authentication
Steve Prentiss
set up on a remote access portal.
Cybersecurity Analyst
This according to HHS Cybersecurity Director Charlie Hess.
Steve Prentiss
At a recent conference, she said, we
Cybersecurity Analyst
realize there are third party risks lurking in our healthcare system and we don't
Steve Prentiss
even know they are there. End Quote Massive Android banking malware poses as an IPTV app researchers at ThreatFabric
Cybersecurity Analyst
have named this new Android banking malware Massive. That is Massiv. It poses as an IPTV app that is Internet Protocol Television to steal digital identities and access online banking accounts.
Steve Prentiss
The malware quote relies on screen overlays
Cybersecurity Analyst
and key logging to obtain sensitive data and can take remote control of a
Steve Prentiss
compromised device, the researchers observed.
Cybersecurity Analyst
MASV Target, a Portuguese government app that
Steve Prentiss
connects with Portugal's digital authentication and signature system.
Cybersecurity Analyst
Such a procedure could be used to bypass know your customer verifications or to access banking accounts and other public and private online services. It's Friday, but let's start thinking about
Steve Prentiss
how to get next week off to a good start.
Cybersecurity Analyst
Instead of dreading a return to office
Steve Prentiss
drudgery, why not look forward to the
Cybersecurity Analyst
best cybersecurity news briefing around? We live stream the Department of no every Monday at 4pm Eastern, breaking down the news of last week and giving
Steve Prentiss
you the insights you need to bring to your team.
Cybersecurity Analyst
Join our two security leader guests in our lively chat room, ask some questions
Steve Prentiss
and join in on the conversation. Be sure you're subscribed to the CISO
Cybersecurity Analyst
Series YouTube channel to join us each
Steve Prentiss
and every week at 4pm Eastern.
Cybersecurity Analyst
And if you have some thoughts on
Steve Prentiss
the news from today or about this
Cybersecurity Analyst
show in general, please be sure to
Steve Prentiss
reach out to us@feedbackisoseries.com we would love to hear from you, Steve I'm Steve Prentice reporting for the CISO Series.
Host
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Host: Steve Prentiss | Podcast: CISO Series
This episode of the Cybersecurity Headlines podcast offers a rapid-fire roundup of significant cybersecurity news stories impacting global organizations, individuals, and governments. Key themes include urgent critical vulnerabilities, the evolution of malware using AI, browser-based threats, advanced phishing kits, global cyberattacks on banking infrastructure, a rise in ATM jackpotting, healthcare sector risks, and sophisticated Android banking malware. The overall tone is urgent and authoritative, with an emphasis on actionable intelligence for security teams.
This tightly packed episode underscores the rapidly evolving attack surface, with stories ranging from supply chain vulnerabilities and sophisticated phishing kits to the use of artificial intelligence in malware and the ongoing risks endemic to the browser and third-party providers. The episode encourages vigilance, rapid response to critical patches, basic digital hygiene, and a renewed focus on third-party and endpoint security, providing timely, actionable insights for CISOs and security professionals.