Skip to content
Ivanti actor identified, search overviews manipulated, ClickFix leverages Nslookup

Ivanti actor identified, search overviews manipulated, ClickFix leverages Nslookup

Linkedin February 16, 2026

“A single IP address hosted on bulletproof infrastructure is responsible for over 83% of exploitation activity related to two vulnerabilities,” says intelligence company GreyNoise. The two CVE numbered vulnerabilities exist in Ivanti Endpoint Manager Mobile (EPMM) – (CVE-2026-21962 and CVE-2026-24061) and have been “flagged as actively exploited in zero-day attacks in Ivanti’s security advisory, where the company also announced hotfixes.” The source of these attacks is an IP address hosted by PROSPERO OOO, which “Censys analysts marked as a bulletproof autonomous system used to target various software products.”

From the “this is why we can’t have nice things” department, Google’s AI Overviews feature is being “weaponized by scammers who’ve figured out how to inject deliberately harmful information into its AI-generated summaries by reverse-engineering how Google’s AI sources information. This allows them to plant malicious content such as “links to phishing sites disguised as customer service portals, promoting counterfeit products as legitimate recommendations, and spreading misinformation designed to build trust before hitting victims with financial scams.” Experts emphasize that users should treat AI Overviews as a starting point that requires verification, rather than as a definitive answer.

The increasingly popular ClickFix social engineering tactic has a new angle, in which attackers “trick users into running commands that carry out a Domain Name System (DNS) aka “nslookup” (short for nameserver lookup) to retrieve the -stage payload.” In this case it performs a DNS lookup against a hard-coded external DNS server, rather than the system’s default resolver,” said Microsoft’s Threat Intelligence team. “Using DNS in this way reduces dependency on traditional web requests and can help blend malicious activity into normal network traffic,” the Windows maker added.

Physical letters sent through the postal service are urging users of the two cryptocurrency hardware wallets into submitting recovery phrases as part of a fictional authentication check. The letters include company logos, and other letterhead features as do the envelopes. The messages conveyed urgency, warning users to complete the process by February 15, 2026, yesterday, or risk losing functionality on their devices. It should be noted that both Trezor and Ledger suffered data breaches in the past couple of years that have exposed customer information.

Kaupo Rosin, Estonia’s foreign intelligence chief, called on European governments and industry to “invest in homegrown offensive cyber capabilities, noting that the continent relies too heavily on non-European tools.” Speaking on Friday at the Munich Cyber Security Conference, he said, “Europe is focused on defense, while modern intelligence and security operations increasingly depend on the ability to penetrate, disrupt or manipulate adversaries’ digital systems,” and that he would “love to coordinate and cooperate with Europeans more on that.”

Following backlash from consumers concerned privacy, Amazon-owned Ring has cancelled its partnership plans with Flock Safety, a police surveillance tech company best known for automated license plate reader (ALPR) cameras. The Ring Super Bowl ad showed how people’s Ring cameras could be used to help locate lost dogs, but the wording of the ad “raised questions how the facial recognition-enabled cameras can also be used to surveil and monitor the movements of people.” Ring still maintains a Community Requests program with another major police surveillance tech company called Axon.

The Netherlands’ largest mobile network operator has state that a breach of its customer system may have affected around 6.2 million people. The data affected includes PII and bank account numbers. The telco says, however, that passwords, call details, billing or location data, or scans of the ID documents” could not have been accessed. The breach was noticed last weekend and was reported to the Dutch Data Protection Authority.

According to researchers at PromptArmor, attackers are now starting to use malicious prompts inside messaging apps to “trick an AI agent into generating a data-leaking URL, which link previews may fetch automatically.” These link previews can “turn URLs generated by an AI agent and controlled by an attacker into a zero-click data-exfiltration channel, allowing sensitive information to be leaked without any user interaction.” PromptArmor notes in its report, that this technique removes the need for a victim to click a link, thus making the problem, especially inside messaging platforms like as Slack and Telegram, where link previews are enabled by default, a whole lot worse.

Spotify , Apple Podcasts , YouTube , RSS link , Amazon Music , add as an Alexa Skill , or "Cybersecurity Headlines" on your favorite podcast app.