Transcript
A (0:02)
You're listening to the Cyberwire Network powered by N2K. Cyber threats strike in minutes. Your analysis can't take weeks. That's where Velox Reverser from Booz Allen comes in. It's an autonomous malware reverse engineering and threat intelligence product that turns weeks of painstaking manual analysis into minutes of AI powered insight sites. With Velox Reverser security teams can perform deep analysis to learn how malware works and how to stop it. It's an advanced product that works at machine speed if you need to outpace evolving adversaries and strengthen your defense at scale. Request a demo or start your 30 day free trial of Velux Reverser today at Booz Allen.com Reverser. Dutch authorities warn Russia is escalating hybrid operations across Europe. Ransomware shuts down the University of Mississippi Medical Center. PayPal notifies customers of a data breach. The FBI says ATM jackpotting is on the rise. Trust Connect Malware masquerades as a legitimate remote monitoring and management tool. Researchers uncover the first Android malware to integrate generative AI. A critical zero day hits Grand Stream voiceover IP phones the IRS slashes IT staff and technology executives Our guest is James Tergal, a 22 year FBI vet and VP of Global Cyber Risk and Board Relations at Optiv, discussing the latest wave of tax scams and IRS fraud and Doge dudes deliver DEI death blows. It's Friday, February 20th, 2026. I'm Dave Buettner and this is your Cyberwire Intel Briefing. Thanks for joining us on this rainy Friday here in the dmv. It is great to have you with us. Russia is escalating hybrid operations across Europe as it prepares for a prolonged confrontation with the west, according to a new joint assessment from the Netherlands General Intelligence and Security Service and Military Intelligence and Security Service. The Dutch agencies report a sharp rise since late 2023 in cyber attacks, sabotage, disinformation, espionage and covert political influence designed to remain below the threshold of open war. While a direct Russian NATO conflict remains unlikely, it's no longer unthinkable, they warn. The Netherlands has faced distributed denial of service attacks, espionage targeting police systems and activity probing critical infrastructure. Moscow is also mapping seabed infrastructure and relying more on low level agents recruited online. Dutch officials say Russia's risk tolerance has increased and the campaign is likely to continue in waves. The report urges stronger national resilience and closer public private cooperation to counter a sustained asymmetric threat. A ransomware attack struck the University of Mississippi Medical center on Thursday, shutting down its IT network. Electronic medical records system and clinics statewide. University leaders confirmed the attack forced widespread cancellations of appointments and elective surgeries, with emergency services continuing under downtime protocols. The electronic medical records platform was among the affected systems. Mississippi MedCom, which coordinates hospital transfers, was also disrupted but continues operating through redundancies. An FBI official said it's too early to identify the ransomware variant or origin. The full scope of potential data exposure remains unclear. Patients reported canceled procedures, including chemotherapy and difficulty contacting providers. Experts warn ransomware can significantly worsen patient outcomes and prolong disruptions for weeks or months. Hospital leadership said reducing clinical volume is necessary to stabilize operations. While the investigation continues, PayPal is notifying customers after a software error in its PayPal working capital loan application exposed sensitive data for nearly six months in 2025. The company says names, contact details, Social Security numbers and dates of birth were accessible from July 1 through December 13 before the issue was discovered and fixed. A small number of accounts saw unauthorized transactions, which PayPal says have been refunded. The company reset affected passwords and is offering two years of credit monitoring through Equifax. PayPal has not disclosed how many customers were impacted. The FBI says Americans lost more than $20 million last year in a sharp rise in ATM jackpotting attacks. In a recent flash alert, the bureau reported more than 700 incidents in 2025 alone, compared to about 1,900 total since 2020. These attacks use malware such as Plautus to bypass bank authorization by exploiting the Extensions for financial services or XFS, software layer inside ATMs. Criminals typically gain physical access with generic keys, install the malware on the machine's hard drive and TR cash withdrawals without a card or account. The FBI advises financial institutions to audit for unauthorized storage use and suspicious processes. The warning follows justice department charges against 87 alleged trendy Aragua members tied to jackpotting schemes. In a Manhattan courtroom, Arkansas Dr. David Churchill described discovering his 27 year old son, Reed, dead from fentanyl laced pills purchased on the Dark Web marketplace incognito. The site's administrator, 25 year old Lin Ru Sang of Taiwan, was sentenced to 30 years in prison for running the platform, which facilitated more than $100 million in drug sales before shutting down in 2024. At sentencing, Lynn's defense revealed that an FBI confidential informant had helped moderate the marketplace for nearly two years. According to Wired. Court filings alleged the informant had authority to remove fentanyl sellers but at times allowed flagged vendors to continue operating. Prosecutors argued the informant acted as Lynn's subordinate and that Lynn knowingly enabled opioid sales. The judge expressed skepticism about the FBI's prolonged involvement, but ruled that any government role did not diminish Lyn's responsibility. Lyn has filed an appeal. Proofpoint has identified a new malware as a service platform called Trust Connect that masquerades as a legitimate remote monitoring and management tool. The Service, advertised at $300 per month, operates through a fake business website that doubles as its command and control server and customer portal. Threat actors distributed the signed malware in late January 2026 using lures such as Meeting Invites and Tax Doc, often alongside legitimate remote access tools like Screen Connect and LogMeIn. Trust Connect provides a web based dashboard for managing infected devices, executing commands, and deploying additional payloads. Proofpoint coordinated disruption of its infrastructure and revoked a fraudulently obtained extended validation certificate used to sign the malware. The operator has since pivoted to new infrastructure promoting a similar tool called Doc Connect. Researchers assess with moderate confidence that the actor was previously linked to Redline Stealer activity Researchers at ESET have identified what they say is the first Android malware to integrate generative AI directly into its execution flow. The malware dubbed Prompt Spy abuses Google's Gemini model to adapt how it maintains persistence across different Android devices. Because app pinning methods vary by manufacturer, PromptSpy sends Gemini an XML dump of the screen and receives JSON instructions on how to lock itself in the recent Apps list. It then executes those steps using Android's Accessibility service in a feedback loop until persistence is achieved. Beyond this AI driven feature, the malware functions as spyware, enabling remote screen control, credential interception, screenshots and app monitoring. Although distribution appears limited and may be proof of concept, researchers say it demonstrates how generative AI can dynamically guide malware behavior in real time. Rapid7 Labs has disclosed a critical zero day vulnerability affecting all Grandstream GXP 1600 series voice over IP phones. The flaw is an unauthenticated stack based buffer overflow in the device's web based API service. Accessible in default configurations. With a CVSS score of 9.3, it allows remote code execution with root privileges. Rapid7 demonstrated the exploitation using a Metasploit module, showing attackers could extract stored credentials and potentially reconfigure devices to route calls through a malicious SIP proxy. Grandstream has released firmware updates to remediate the issue. The IRS has lost 40% of its IT staff and nearly 80% of its technology executives, marking its largest tech reorganization in 20 years. Speaking at an association of government accountants panel. IRS CIO Kashit Pandya said the cuts followed broader federal workforce reductions in 2025, when the agency lost a quarter of its overall staff. The IT division began the year with roughly 8,500 employees. About 1,000 technologists were reassigned to frontline tax season support, a move that drew internal criticism. Pandya said the shakeup aims to break down silos and create cross functional teams, which focused on end to end delivery. However, the treasury inspector general warned that IT staffing losses could jeopardize implementation of tax law changes for the 2026 filing season. AI is expected to support remaining staff. Coming up after the break, James Turgall from Optiv discusses the latest wave of tax scams and IRS fraud and Doge dudes deliver DEI death blows Stick around. When it comes to mobile application security, good enough is a risk. A recent Survey shows that 72% of organizations reported at least one mobile application security incident last year, and 92% of responders reported threat levels have increased in the past two years. Guard Square delivers the highest level of security for your mobile apps without compromising performance, time to market or user experience. Discover how Guard Square provides industry leading security for your Android and iOS apps at www.guardsquare.com. Most Security Conferences Talk about Zero Trust Zero Trust World puts you inside. This is a hands on cybersecurity event designed for practitioners who want real skills, not just theory. You'll take part in live hacking labs where you'll attack real environments, see how modern threats actually and learn how to stop them before they turn into incidents. But Zero Trust World is more than labs. You'll also experience expert led sessions, practical case studies and technical deep dives focused on real world implementation. Whether your Blue team, Red team or responsible for securing an entire organization, the content is built to be immediately useful. You'll earn CPE credits, connect with peers across the industry and leave with strategies you can put into action right away. Join us March 4th through the 6th in Orlando, Florida. Register now at ztw.com and take your zero trust strategy from Theory to execution. James Turgal is a 22 year old veteran of the FBI and currently VP of Global Cyber Risk and Board Relations at Optiv. I sat down with him to learn more about the latest wave of tax scams and IRS fraud. So today we're talking about tax scams and IRS fraud. You know James, this is a sort of an annual thing as it comes up on tax season here, but I can't help feeling like we're in a little different situation when it comes to this tax season because of the prevalence of AI scams, is that an accurate perception on my part?
