Venkat Mangudi

Writing on cybersecurity, AI, resilience, leadership, and risk.

Follow

Signal Watchtower: Edition 003, 2026

The Signal Watchtower: Security, Privacy, AI
Edition 003

FocusSecurity · Privacy · AI

Published27 February 2026

AuthorVenkat Mangudi

February Edition — Published: Feb 27 2026

Executive Overview

February’s cyber-threat landscape continued to underscore the primacy of identity exploitation and data publication as principal risk vectors.

There was definitive movement from post-extortion publication of datasets in multiple instances, a continued rise in ambient credential circulation, and a significant pattern of social engineering-enabled access preceding high-impact data exposures. At the vulnerability level, CISA expanded the Known Exploited Vulnerabilities (KEV) catalog with multiple entries tied to active exploitation — particularly browser and webmail vectors.

Enterprise defenders should prioritize patching publicly exploited vulnerabilities and harden authentication and credential practices to mitigate the downstream identity risk imposed by circulating datasets and ambient credentials.

Confirmed Disclosures and Company-Acknowledged Investigations

Odido (Netherlands telecom) — Confirmed

Dutch telecom provider Odido confirmed unauthorized access to its customer management system, with threat actors reportedly extracting personal data — including sensitive identifiers — for millions of customers. Incident investigations are ongoing and notifications to affected customers are expected as part of regulatory requirements.

Conduent — Confirmed / Investigating (Regulatory Phase)

The data breach at Conduent continues to expand in scope based on regulatory filings and attorney-general investigations, with potential multi-million individual impacts reported and formal state-level inquiries launched.

PayPal Working Capital Exposure — Confirmed

PayPal disclosed an exposure involving its Working Capital loan platform stemming from a control failure, resulting in unauthorized access to applicant data. The incident is classified as a software-driven exposure rather than a core payments system compromise.

Crunchbase — Confirmed dataset circulating

Crunchbase confirmed a breach following public reporting of leaked data after extortion attempts failed. The dataset continues to circulate and drive downstream risk.

Figure (fintech lending) — Confirmed dataset circulating

Figure confirmed an incident tied to social engineering, with associated personal data circulating — now indexed by major breach tracking platforms.

ApolloMD (healthcare) — Confirmed

ApolloMD publicly acknowledged a breach affecting patient and provider data; notifications and disclosures reached regulatory portals during February.

Leak-Site and Underground Claims (Unverified)

These items are claimed by threat actors or underground sources, and are unverified by the impacted organizations at time of publication.

Adidas — Claimed (Unverified)

There are underground site claims alleging compromise of Adidas third-party/extranet data, though Adidas corporate has not issued a confirmed disclosure at this time.

McDonald’s India — Claimed (Unverified)

Ransomware group claims a breach of McDonald’s India systems; to date, there is no confirmation from the company or regulator.

Raaga — Claimed (Unverified)

A threat actor claimed to have exfiltrated ~10.2 million user records associated with Raaga, with no corporate confirmation.

Data Published Publicly (Confirmed Circulation)

Datasets reported and verified to be publicly circulating in reputable breach tracking platforms.

CarGurus — Dataset Published / Confirmed Circulation

CarGurus data was added to major breach indices in February, indicating confirmed dataset circulation.

Substack — Dataset Published / Confirmed Circulation

Substack data from a prior 2025 breach was loaded into widely referenced breach indices in early February, reflecting continued availability.

CarMax — Dataset Published / Confirmed Circulation

CarMax data was published and indexed in February, demonstrating confirmed circulation.

Canada Goose — Dataset Published / Confirmed Circulation

Canada Goose breach data from a prior incident appeared in public breach repositories during February.

University of Pennsylvania — Dataset Published / Confirmed Circulation

UPenn breach data was indexed in February, confirming dataset availability beyond the initial incident window.

Ambient Credential Exposure & Identity Commons

149 Million Cross-Platform Credential Corpus — Ambient Credential Exposure

A substantial corpus of approximately 149 million leaked credentials tied to infostealer sources and cross-platform reuse continues to circulate, representing a systemic identity risk (account takeover, credential stuffing, fraud) independent of any single platform breach. Analysts should treat this as an ambient identity commodity fueling attack automation rather than a breach of specific services.

Signals & Patterns

  • Social engineering remains the principal initial access vector in multiple confirmed incidents, highlighting that technical control failures are often preceded by human-targeted manipulation.
  • Data publication post-extortion is now the default outcome following failed ransomware negotiations, compressing defender timelines for response and increasing secondary harm.
  • Third-party concentration risk persists; breaches at service providers (e.g., Conduent) propagate impacts to dependent entities, complicating regulatory and notification landscapes.
  • Healthcare disclosure latency continues, with incidents occurring well before formal public clarity emerges, underscoring challenges for timely protective actions.

Monthly Exploitation and Vulnerability Roundup

CISA Known Exploited Vulnerabilities (KEV) Additions — February 2026

During February, the U.S. Cybersecurity and Infrastructure Security Agency updated the Known Exploited Vulnerabilities (KEV) catalog with multiple entries based on confirmed active exploitation evidence. These include browser memory corruption and webmail platform flaws that have been weaponized in the wild.

Organizations should use the KEV catalog as the authoritative input for urgent patching queues.

Actively Exploited Zero-Days Addressed — February Patch Activity

Microsoft’s February Patch Tuesday fixed roughly 59 vulnerabilities, including six zero-days confirmed as actively exploited, spanning SmartScreen bypasses, Office file handling bypasses, privilege escalation vectors, and other critical workflows. Prioritize these in enterprise patch cycles.

Browser Exploitation — CVE-2026-2441

A confirmed Chrome zero-day (CVE-2026-2441) was publicly reported with in-the-wild exploitation, underscoring the need for rapid browser updates across enterprise environments. Crisis response should include version floor verification, relaunch proofing, and telemetry confirmation for fleet compliance.

Internet-Facing Webmail — Roundcube KEV Additions

CISA added critical vulnerabilities affecting a widely deployed webmail platform to the KEV list based on observed exploitation, emphasizing credential capture and session takeover pathways as high-impact threats.

Edge Appliance Campaign — FortiGate Credential Abuse

A financially motivated actor leveraged exposed management ports and weak credentials to compromise over 600+ FortiGate devices across ~55 countries without necessarily exploiting a zero-day, illustrating that perimeter misconfigurations and basic credential hygiene remain exploitable at scale by commoditized attackers.

Defender Actions

  1. Prioritize Identity Hardening
  2. Use KEV as the Patch Urgency Baseline
  3. Accelerate Zero-Day Mitigation Lifecycle
  4. Third-Party Risk Visibility
  5. Credential Economy Monitoring

Originally published on LinkedIn: www.linkedin.com/pulse/edition-003-2026-venkat-mangudi-cghhc


Discover more from Venkat Mangudi

Subscribe now to keep reading and get access to the full archive.

Continue reading