WEF 2026 Cybersecurity Outlook, VoidLink, BeyondTrust RCE, and Microsoft zero-days


Listen to Article

0:00 / 0:00

It’s a Paper Trail for the week ending in Feb 14, 2026 and we’ll cover what happened last week in the Information Security space.

Last Week, in Review

  • Microsoft, in its latest February Patch Tuesday release, patched 59 CVEs – including actively exploited 6 zero-days. 
  • According to the BlackFog 2025 Report, while a 49% YoY increase in reported ransomware attacks was observed, 86% of the ransomware attacks go unreported.  
  • As indicated in the World Economic Forum’s 2026 Global Cybersecurity Outlook, CEOs’ top cyber risk concerns include cyber-enabled fraud and phishing, AI vulnerabilities, and exploitation of software vulnerabilities – differing from CISOs’ top concerns: ransomware attacks, supply chain disruption, and exploitation of software vulnerabilities.

Pulse

VoidLink – a Cloud-first Malware Framework: VoidLink – an advanced malware framework built to gain longer-term Linux access persistence across multiple cloud providers (Amazon AWS, Google GCP, Microsoft Azure, Alibaba Cloud, Tencent Cloud) to steal credentials, escapes containers, and hides at the kernel level using encrypted traffic that mimics normal web activity. Some mitigations include deploying an EDR for Linux platforms, hardening container and K8s environments, monitoring usage of metadata endpoints, and strong network segmentation. [The Hacker News (Jan 21, 2026); Cisco Talos (Feb 10, 2026); Darkreading (Jan 21, 2026); Checkpoint (Jan 13, 2026)]

Blockchain-native financial services and lending platform – Figure – affected by phishing: Figure recently disclosed a breach after an employee became a victim of social engineering, which allowed the threat actors access to limited amounts of data. [TechCrunch (Feb 13); Security Affairs (Feb 14, 2026)] 

Fix-it Frank

Microsoft releases patches for 59 CVEs, including 6 zero-days: Microsoft released patches for 59 CVEs on Feb 10, including 6 zero-days already being exploited in the wild. Key zero-days include CVE-2026-21510 (Windows Shell), CVE-2026-21513 (Windows), and CVE-2026-21514 (Word security feature bypass). With targeting of flaws for GitHub Copilot, Visual Studio Code, and Azure SDK adds one more instance of a shift in the software supply chain farther left and into the IDE. [CybersecurityNews (Feb 10, 2026); CrowdStrike (Feb 10, 2026)] 

Solarwinds web helpdesk under active multi-stage attacks: Microsoft and Huntress both reported active exploitation of SolarWinds Web Help Desk (WHD) instances across multiple customer environments. Attackers used critical RCE flaws (CVE-2025-40551, CVSS 9.8) to gain initial access, then deployed Zoho ManageEngine and Velociraptor for persistence, used living-off-the-land techniques, and set up reverse SSH shells. In an attack like this, attackers used legitimate admin tools to stay hidden, making detection extremely difficult with traditional security controls. SolarWinds WHD should be updated to version 2026.1 or later to remediate the identified vulnerability. As an additional measure, the organization should perform targeted threat hunts to identify unauthorized RMM tools. [The Hacker News (Feb 9, 2026); Huntress (Feb 8, 2026); Microsoft Defender Research (Feb 6, 2026)]

BeyondTrust RCE exploited without hours of PoC release: Attackers began exploiting a critical RCE vulnerability in BeyondTrust Remote Support and Privileged Remote Access within hours of a proof-of-concept being published, demonstrating that the time from PoC to exploitation is shrinking to hours, not days. It is recommended to patch BeyondTrust Remote Support and Privileged Remote Access tooling to the latest version and limit its access from the Internet in the event patches cannot be applied. [The Hacker News (Feb 9, 2026)]

287 Malicious Chrome extensions stole data from 37.4 million users: Security researcher Q Continuum discovered 287 Chrome extensions secretly transmitting browsing data to remote servers and data brokers. The extensions have 37.4 million combined installations – roughly 1% of Chrome’s global user base. Separately, an “AiFrame” campaign of 32 extensions marketed as AI assistants was found exfiltrating data. Another extension, “CL Suite,” targeted Meta Business Suite credentials and TOTP codes. Organizations should review existing extensions and implement extension allowlist to limit the potential risk posed by unvetted browser extensions. [SecurityWeek (Feb 14, 2026); The Hacker News (Feb 13, 2026); The Register (Feb 11, 2026); Socket (Feb 13, 2026)]

The Fine Print

Conduent breach affects 25M+ people; Texas AG launches investigation: Conduent, a business technology firm offering services for various government programs, experienced a ransomware attack in January 2025 and the exposed data includes SSN, medical records, and insurance details. This has affected more than 25M people across the United States – making it the 8th largest healthcare data breach in the country’s history. In addition to an investigation from Texas AG, the company also faces 8 class action lawsuits in New Jersey. [TechCrunch (Feb 5, 2026); Fox Business (Feb 9, 2026); Texas AG Press Release (Feb 12, 2026); SecurityWeek (Feb 11, 2026); HIPAA Journal (Feb 13, 2026)]

India introduces framework to regulate AI-generated content with new deepfake rules: India enacts a regulation G.S.R 120(E), effective Feb 20, 2026, that formally defines Synthetically Generated Information (SGI), the labeling requirements, and mandatory requirements for disclosure for AI-generated content – including deepfakes. This makes it one of the early national frameworks providing governing requirements around SGI. [The Policy Edge (Feb 11, 2026); MEITy, India]

The Bottom Line

Threat activity is trending toward faster exploitation from zero-days to rapid PoCs to weaponization and stealthier access. At the same time, phishing-driven breaches and emerging deepfake regulation signal a growing convergence of operational security risk and governance pressure.