Week 7 - 2026 Weekly Digest

09 Feb 2026 – 15 Feb 2026 • Published: 16 Feb 2026

CVE News Ransomware 8Bit Content Week 7 2026

Critical CVEs

CVE-2026-21510 — Windows SmartScreen Bypass CVSS 8.8

Microsoft Windows Shell

An attacker could bypass Windows SmartScreen and Windows Shell security prompts, enabling the execution of malicious content without requiring user consent.

CVE-2026-20841 — Malicious Markdown Link CVSS 7.8

Microsoft Notepad

This vulnerability could allow an attacker to execute code locally. To exploit it, the attacker would need to persuade the victim to click a malicious link embedded within a Markdown file opened through Notepad. Se vuoi, posso anche fornirti un short title o una versione più tecnica per CVE/advisory.

CVE-2026-20700 — Memory Corruption Issue CVSS 7.8

Apple macOS, iOS, iPadOS

A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 26.3, tvOS 26.3, macOS Tahoe 26.3, visionOS 26.3, iOS 26.3 and iPadOS 26.3. An attacker with memory write capability may be able to execute arbitrary code. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26. CVE-2025-14174 and CVE-2025-43529 were also issued in response to this report.

Top Security News

Claude LLM artifacts abused to push Mac infostealers in ClickFix attack News

Threat actors are abusing Claude artifacts and Google Ads in ClickFix campaigns that deliver infostealer malware to macOS users searching for specific queries. At least two variants of the malicious activity have been observed in the wild, and more than 10,000 users have accessed the content with dangerous instructions.

Source: BleepingComputer

Microsoft Under Pressure to Bolster Defenses for BYOVD Attacks News

Over the past year, threat actors — most notably, ransomware groups — have increasingly embraced the BYOVD technique to disable security products in a targeted network. The technique involves threat actors identifying a vulnerable driver that they can exploit and dropping it on a targeted system. Attackers then use the kernel-level access and elevated privileges of the driver to kill security processes on a system before deploying their payload, be it ransomware, infostealers, or backdoors.

Source: DarkReading

CISA flags critical Microsoft SCCM flaw as exploited in attacks News

CISA has stated that the SQL injection vulnerability CVE‑2024‑43468, affecting Microsoft SCCM, is currently being exploited in the wild.

Source: BleepingComputer

Ransomware Activity

Bitgo Ransomware

The threat actor Incransom claims responsibility for a ransomware attack against the victim in the Information & Communication Technology sector on February 14.

A.T.I di Zuinisi Ransomware

The threat actor Nightspire claims responsibility for a ransomware attack against the victim in the Construction sector on February 14.

Siem Ransomware

The threat actor spacebears claims responsibility for a ransomware attack against the victim in the Avionics sector on February 13.