Skip to content
Multiple Cybersecurity Incidents and Vulnerabilities Reported in February 2026

Multiple Cybersecurity Incidents and Vulnerabilities Reported in February 2026

First seen 12 Feb 2026, 21:16 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 17, 2026 at 18:27 UTC

In February 2026, various cybersecurity incidents were reported, including the exploitation of Ivanti EPMM vulnerabilities linked to a single IP address and the discovery of malicious packages by the Lazarus group in npm and PyPI ecosystems. Additionally, Microsoft issued patches for 59 vulnerabilities, including six that were actively exploited. APT36 and SideCopy also launched new cross-platform attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 178d ago How this analysis works

Timeline

2026-02-10
Reynolds Ransomware embeds BYOVD driver to disable EDR tools
2026-02-10
APT36 and SideCopy launch new cross-platform attacks
2026-02-11
Microsoft patches 59 vulnerabilities, including six actively exploited
2026-02-11
Over 60 software vendors issue security fixes across platforms
2026-02-12
83% of Ivanti EPMM exploits linked to single IP on bulletproof hosting
2026-02-12
Lazarus campaign plants malicious packages in npm and PyPI ecosystems
2026-02-12
ThreatsDay Bulletin reports on multiple new vulnerabilities and exploits

More articles in this cluster (52)

Following this threat?

Track Reynolds, Apt36 and RenEngine Loader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed