BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
Threat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Nation-State Roundup: CISA KEV Updates, North Korean IT Infiltration, and Russian Hybrid Warfare Escalation

Nation-State Roundup: CISA KEV Updates, North Korean IT Infiltration, and Russian Hybrid Warfare Escalation

February 21, 2026Nation-State & APT3 min readcritical

Originally reported by Security Affairs, The Record

#cisa-kev#roundcube#north-korea#russia#hybrid-warfare#paypal-breach#romanian-cybercrime#eu-regulation
Share

TL;DR

CISA adds exploited RoundCube flaws to KEV, Ukrainian sentenced for North Korean IT worker scheme, PayPal breach exposes data for six months, and Dutch intelligence warns of escalating Russian hybrid...

Why critical?

CISA's addition of RoundCube vulnerabilities to the KEV catalog indicates confirmed active exploitation of these flaws, warranting critical severity.

CISA Adds Exploited RoundCube Webmail Vulnerabilities to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two RoundCube webmail vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. RoundCube, a widely deployed webmail platform, has become a recurring target for threat actors seeking to compromise email communications.

The KEV catalog addition signals that federal agencies and critical infrastructure operators must prioritize patching these vulnerabilities according to CISA's binding operational directive timelines.

PayPal Discloses Six-Month Data Breach from Loan App Software Bug

PayPal disclosed a data breach affecting its PayPal Working Capital loan application that exposed sensitive customer information for approximately six months. The breach, caused by a software error, compromised business contact details including names, email addresses, phone numbers, and physical addresses.

According to PayPal's disclosure, some customers' Social Security numbers were also exposed during the incident. The company has since remediated the software flaw and notified affected customers.

Ukrainian Sentenced for North Korean IT Worker Identity Theft Scheme

Oleksandr "Alexander" Didenko, a 29-year-old Ukrainian national, received a five-year federal prison sentence for his role in facilitating North Korea's fraudulent IT worker infiltration campaign. Didenko admitted to stealing U.S. identities to help North Korean operatives secure employment at approximately 40 American companies.

The scheme represents a significant component of North Korea's broader strategy to generate revenue while potentially conducting espionage and intellectual property theft from within targeted organizations. Federal prosecutors have increasingly prioritized dismantling these "laptop farm" operations that allow sanctioned North Korean workers to circumvent employment restrictions.

Romanian Hacker Pleads Guilty in Oregon Emergency Management Breach

Catalin Dragomir, a Romanian national, pleaded guilty to charges related to breaching Oregon's emergency management department systems. Dragomir faces up to seven years in prison after admitting to obtaining information from protected computers and aggravated identity theft.

The case highlights continued targeting of state and local government systems by international cybercriminals, particularly critical infrastructure and emergency response agencies.

X Challenges EU's €120 Million Fine in Court Appeal

Elon Musk's social media platform X filed an appeal with the European Union's General Court challenging a €120 million ($141 million) fine imposed by the European Commission. The appeal represents X's formal legal challenge to what constitutes one of the largest regulatory penalties against the platform under EU jurisdiction.

The fine stems from alleged violations of EU regulations, though specific details of the underlying violations were not disclosed in available reporting.

Dutch Intelligence Warns of Escalating Russian Hybrid Warfare

Dutch intelligence agencies issued warnings that Russia is significantly intensifying cyberattacks, sabotage operations, and covert influence campaigns across Europe. According to the assessment, these activities indicate the Kremlin's preparation for a prolonged confrontation with Western nations.

The intelligence evaluation suggests Russian hybrid warfare capabilities are expanding beyond traditional cyber operations to encompass broader destabilization efforts targeting European infrastructure and democratic institutions. This assessment aligns with similar warnings from other NATO intelligence services regarding Russia's evolving threat posture.

Sources

  • https://securityaffairs.com/188324/security/u-s-cisa-adds-roundcube-webmail-flaws-to-its-known-exploited-vulnerabilities-catalog.html
  • https://securityaffairs.com/188309/data-breach/paypal-discloses-extended-data-leak-linked-to-loan-app-glitch.html
  • https://securityaffairs.com/188305/cyber-crime/north-korean-it-worker-scam-nets-ukrainian-five-year-sentence-in-the-u-s.html
  • https://therecord.media/romanian-hacker-faces-7-years-oregon-breach
  • https://therecord.media/north-korea-laptop-farm-ukraine
  • https://therecord.media/musk-x-appeal-europe-fine
  • https://therecord.media/russia-cyberattacks-europe-warfare

Originally reported by Security Affairs, The Record

Tags

#cisa-kev#roundcube#north-korea#russia#hybrid-warfare#paypal-breach#romanian-cybercrime#eu-regulation

Related Intelligence

  • Nation-State Roundup: Russian AI-Powered Campaigns and Hybrid Warfare Operations

    highFeb 23, 2026
  • Critical BeyondTrust RCE Under Active Exploitation, Romanian Hacker Pleads Guilty to State Network Breach

    criticalFeb 23, 2026
  • Russian Hacker Leverages AI to Breach 600+ Fortinet Firewalls Across 55 Countries

    criticalFeb 22, 2026

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← Privacy & Surveillance Roundup: DHS Expands Biometric Reach While Tech Partnerships Fragment

Next Article

Security Clearance Form Failures: A 1988 Lesson in Operational Security →