BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
Threat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Active RoundCube Exploitation, AI-Generated Stealers, and France's FICOBA Breach

Active RoundCube Exploitation, AI-Generated Stealers, and France's FICOBA Breach

February 23, 2026Malware & Threats2 min readcritical

Originally reported by BleepingComputer, Checkpoint Research, Malwarebytes Labs

#roundcube#cisa-kev#info-stealer#ai-malware#data-breach#threat-intelligence#active-exploitation
Share

TL;DR

CISA flags actively exploited RoundCube flaws, researchers analyze AI-generated Arkanix Stealer, and France discloses 1.2M account breach in national banking registry.

Why critical?

CISA added actively exploited RoundCube vulnerabilities to the KEV catalog, indicating confirmed exploitation in the wild requiring immediate federal agency response.

CISA Flags Actively Exploited RoundCube Vulnerabilities

CISA added two RoundCube Webmail vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in attacks targeting the open-source webmail platform. Federal agencies must patch these flaws within three weeks under Binding Operational Directive 22-01.

The vulnerabilities affect RoundCube's authentication and session management mechanisms, providing attackers with pathways to compromise webmail accounts. Organizations running RoundCube deployments should prioritize these patches given the confirmed active exploitation.

AI-Assisted Arkanix Stealer Emerges as Short-Lived Experiment

Security researchers analyzed Arkanix Stealer, an information-stealing malware that surfaced on dark web forums in late 2025 before quickly disappearing. The operation appears to have been developed as an AI-assisted experiment, representing an early example of machine learning techniques applied to malware development.

The stealer targeted standard information theft objectives including credentials, cryptocurrency wallets, and browser data. Despite its AI-enhanced development approach, the malware's brief operational window suggests experimental rather than commercial deployment.

France Discloses 1.2 Million Account Data Breach

France's Ministry of Economy disclosed unauthorized access to FICOBA, the national bank account registry, exposing information linked to 1.2 million accounts. The breach compromised names and associated banking data stored in the centralized registry system.

According to Check Point Research's weekly threat intelligence bulletin, the incident represents a significant compromise of financial infrastructure data. French authorities have not yet disclosed the attack vector or timeline for the unauthorized access.

Weekly Security Roundups Released

Both Malwarebytes Labs and Check Point Research published their weekly security summaries covering February 16-22. The reports aggregate threat intelligence findings, breach disclosures, and vulnerability research from the cybersecurity community.

Additionally, Malwarebytes released a podcast episode examining TikTok's new American ownership structure and associated content moderation policies, discussing implications for platform security and user privacy.

Sources

  • CISA: Recently patched RoundCube flaws now exploited in attacks
  • Arkanix Stealer pops up as short-lived AI info-stealer experiment
  • 23rd February – Threat Intelligence Report
  • A week in security (February 16 – February 22)
  • What can't you say on TikTok?

Originally reported by BleepingComputer, Checkpoint Research, Malwarebytes Labs

Tags

#roundcube#cisa-kev#info-stealer#ai-malware#data-breach#threat-intelligence#active-exploitation

Tracked Companies

🇨🇳TikTok

Related Intelligence

  • Critical Infrastructure Under Siege: From Actively Exploited BeyondTrust RCE to Healthcare Ransomware Shutdowns

    criticalFeb 20, 2026
  • Critical VMware RCE Exploited, Major Breaches Hit LexisNexis and AkzoNobel

    criticalMar 4, 2026
  • Treasury Sanctions Russian Exploit Broker as Critical SolarWinds Flaws Hit Servers

    criticalFeb 25, 2026

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← Nation-State Roundup: Russian AI-Powered Campaigns and Hybrid Warfare Operations

Next Article

Weekly Threat Roundup: Vishing Breaches, Zero-Knowledge Gaps, and RAT Distribution Networks →