Microsoft’s February Security Update of High-Risk Vulnerability Notice for Multiple Products

March 4, 2026 | NSFOCUS

Overview On February 11, 2026, NSFOCUS CERT monitored Microsoft’s release of its February security update patches, addressing 59 security issues across widely used products such as Windows, Azure, Microsoft Office, and Visual Studio Code. These vulnerabilities include privilege escalation, remote code execution, and other high-risk vulnerabilities. In this monthly update, 5 vulnerabilities are rated as […]

Imagem que ilustra um ataque cibernético em andamento.

Digital Outposts: Evaluating the Role of DDoS Attacks in US-Iran Conflict

March 2, 2026 | NSFOCUS

Background According to the monitoring data from NSFOCUS Fuying Lab, since the outbreak of domestic conflict in Iran in January 2026 and the subsequent escalation of tensions over the nuclear issue between the U.S. and Iran, Iran has been continuously subjected to DDoS attacks. The attack methods have shown diverse characteristics, including both botnet-based attacks […]

ilustração de como funciona a computação quântica.

Insights into Claude Code Security: A New Pattern of Intelligent Attack and Defense

February 26, 2026 | NSFOCUS

On February 20, 2026, AI company Anthropic released a new code security tool called Claude Code Security. This release coincided with the highly sensitive period of global capital markets to AI technology subverting the traditional software industry, which quickly triggered violent fluctuations in the capital market and caused the fall of stock prices of major […]

Blue Teaming Construction Insights from 2025 Threat Landscape Observations

February 25, 2026 | NSFOCUS

In 2025, AI has evolved from being a tool that merely enhances the efficiency of attacks to becoming an integral component embedded within the execution phase of cyber operations. In the future, AI may even emerge as a pivotal enabler for attack activities. During the initial attack phase, AI technology has significantly reduced the difficulty of […]

Imagem que ilustra como funciona uma criptografia.

Protecting AI Security: 2025 Hot Security Incident

February 23, 2026 | NSFOCUS

GitHub MCP Cross-Repository Data Leak Vulnerability In May 2025, Invariant disclosed a critical vulnerability in GitHub’s Machine Collaboration Protocol (MCP), where attackers embedded malicious commands within public repository Issues to hijack developers’ locally running AI Agents. When an AI Agent was triggered to read and “assist” in processing the Issue, it indiscriminately executed the embedded […]

AI-Empowered Cybersecurity: Key Events and Emerging Trends in 2025

February 20, 2026 | NSFOCUS

In September 2025, Anthropic disclosed a groundbreaking incident—the world’s first autonomous AI-driven cyberattack. This event, documented as the first large-scale cyber offensive primarily executed by AI with minimal human intervention, underscored the immense threat posed by AI agents in malicious applications. The attackers posed as representatives of a legitimate cybersecurity firm conducting a defense assessment. They […]

Top Security Incidents of 2025: Chrome Browser 0-Day Vulnerability Exploitation

February 18, 2026 | NSFOCUS

Background In March 2025, cybersecurity researchers disclosed a highly sophisticated targeted attack campaign named “Operation ForumTroll.” Orchestrated by an unidentified state-sponsored APT group, the operation leveraged a Google Chrome 0-day vulnerability (CVE-2025-2783) as its core weapon. This vulnerability enabled sandbox escape, allowing arbitrary code execution on victims’ Windows systems and granting full control over the targeted […]

Imagem que ilustra como a inteligência artificial pode ser uma fácil entrada para hackers.

Top Security Incidents of 2025: Lazarus Group’s Cryptocurrency Heist

February 16, 2026 | NSFOCUS

Event Summary In February 2025, the North Korea-linked APT group Lazarus launched a highly sophisticated supply chain attack against the prominent cryptocurrency exchange Bybit, successfully stealing over 400,000 ETH and stETH—valued at approximately $1.5 billion. This incident marks the largest single security breach in the global cryptocurrency sector to date. The attack exposed critical vulnerabilities […]

Top Security Incidents of 2025:  The Emergence of the ChainedShark APT Group

February 13, 2026 | NSFOCUS

In 2025, NSFOCUS Fuying Lab disclosed a new APT group targeting China’s scientific research sector, dubbed “ChainedShark” (tracking number: Actor240820). Been active since May 2024, the group’s operations are marked by high strategic coherence and technical sophistication. Its primary targets are professionals in Chinese universities and research institutions specializing in international relations, marine technology, and related […]

OpenClaw Open Source AI Agent Application Attack Surface and Security Risk System Analysis

February 12, 2026 | NSFOCUS

Background In early 2026, OpenClaw (formerly known as Clawdbot and Moltbot), an open-source autonomous AI agent project, quickly attracted global attention. As an automated intelligent application running in the form of a chatbot, it allows users to input natural language commands through Web pages and IM tools (such as Telegram, Slack, Discord, etc.) to achieve […]

Search

Subscribe to the NSFOCUS Blog