Latest Internet & Cybersecurity News

📅February 28, 2026 at 1:00 AM
Major data breaches at Odido, ManoMano, and DJI expose millions; new ransomware suits, state-sponsored threats from China and NK persist; AI tools and products launch amid rising credential attacks.
1

ManoMano Data Breach Exposes 38 Million Customers

ManoMano disclosed a significant data breach from an external service provider compromise detected in early 2026, exposing personal information of approximately 38 million customers.Source 2 The incident highlights ongoing risks to e-commerce platforms from third-party vulnerabilities.Source 2 No specific threat actor has claimed responsibility yet.Source 2

2

ShinyHunters Claim Odido Telecom Data Breach

ShinyHunters announced on BreachForums on February 27, 2026, that they compromised Odido's databases, exposing customer records, internal documents, and plaintext passwords after warning the company on February 24.Source 4 The breach raises risks of identity theft and financial fraud for Dutch telecom users.Source 4 Odido has not confirmed the full scope publicly.Source 4

3

Custodial Institutions Agency Staff Data Exposed

A major data breach compromised personal details of employees at the Netherlands' Custodial Institutions Agency (DJI), confirmed by a spokesperson on February 27, 2026.Source 12 The exposure affects prison staff data, potentially for five months prior.Source 2 Investigations into the breach's scope and impact are ongoing.Source 12

4

Maris Sues SonicWall Over Ransomware Attack

Marqueis Software Solutions is suing SonicWall for negligence after a ransomware attack via a cloud backup security gap impacted 74 U.S. banks.Source 2 The suit claims state-sponsored hackers stole sensitive data.Source 2 This follows SonicWall vulnerabilities exploited in prior incidents.Source 2

5

Google Disrupts Chinese UNC2814 Cyber Espionage

Google collaborated with partners to dismantle UNC2814's infrastructure, a China-linked group that breached 53 organizations globally using cloud services since late 2025.Source 2 The operation targeted freight and transportation platforms, compromising over 1,600 accounts.Source 2 This counters ongoing Chinese espionage efforts.Source 2

6

China's Salt Typhoon and Volt Typhoon Target U.S. Infrastructure

FBI warns Salt Typhoon remains active against U.S. telecoms, while Volt Typhoon persists in critical sectors like energy and transportation.Source 3Source 5 These campaigns aim at sabotage and intelligence, exploiting U.S. cybersecurity gaps.Source 3 Geopolitical tensions drive the threats.Source 5

7

Lazarus Group Targets Crypto Developers and Healthcare

North Korea's Lazarus Group campaigns hit software developers at crypto exchanges and now healthcare with Medusa ransomware.Source 3Source 10 They leverage trusted access for transaction manipulation.Source 3 DPRK blends financial and strategic ops.Source 5

8

UFP Technologies Hit by Cyberattack Disrupting Operations

U.S. medical device maker UFP Technologies suffered a cyberattack around February 14, 2026, disrupting billing and exposing company data.Source 6 Systems were isolated with external help; operations continued via backups.Source 6 Possible ransomware or wiper malware suspected.Source 6

9

Darktrace Report: Rise in AI-Enabled Credential Abuse

Darktrace's 2026 Threat Report notes a shift to faster credential theft over exploits, with 20% more vulnerabilities and AI-phishing evading DMARC.Source 5 CNI faces state and criminal threats amid geopolitics.Source 5 Behavioral AI urged for detection.Source 5

10

New Infosec Products Launched in February 2026

Key releases include SocureGov for government ID verification, Avast Deepfake Guard for scam detection, Portnox passwordless ZTNA, and Aikido Infinite AI pentesting.Source 1 Others like Veza AI Access Agents and Virtana MCP Server enhance enterprise security.Source 1 These address AI risks and zero-trust needs.Source 1

11

CISA Warns of Undetected Resurge Malware on Ivanti

CISA alerted on Resurge malware variant lingering on Ivanti Connect Secure devices post-CVE-2025-0282 exploits.Source 8 It includes log-tampering Spawnsloth and BusyBox for payloads.Source 8 Originally noted in March 2025 attacks.Source 8

12

Ransomware Payments Drop but Attacks Surge in 2025

Chainalysis reports ransomware payments cratered in 2025 despite rising attacks.Source 10 Related: Dutch telco Odido faces second ShinyHunters leak; ex-L3Harris exec jailed for Russia exploits.Source 10 NK's Lazarus hits healthcare.Source 10