From Minecraft to Million-Dollar Theft, MFA Phishing and a Supply-Chain Attack: Weekly Cyber Roundup
Odkazy:
This week in a brief summary of the episode CCTV FLASH we highlighted several key topics: the story of former members of the cybercriminal community “The Com” and the project The Hacking Games, the arrest of the seller of the tool JokerOTP for capturing one-time codes (OTP) to bypass MFA, the first known malicious Outlook add-in observed "in the wild" (AgreeToSteal), active exploitation of the critical flaw CVE-2026-1731 in BeyondTrust products, and two Czech/EU reports from NÚKIB: reporting status under the new cyber law and the new European framework for security of ICT supply chains.
From Minecraft to a Million-Dollar Theft: “The Com” and The Hacking Games
In Manchester two former cybercriminals spoke to students and openly described how easy it is to slip into online crime via gaming communities. One of them, Conor Freeman (26) from Dublin, was in 2020 sentenced to just under three years in prison for involvement in the theft of cryptocurrencies worth about $2 million; the second, Ricky Handschumacher (30) from the USA, served four years for the same case. Both got into “The Com” through gaming and later through dark web forums.
The event was part of an initiative supported by the Co-op chain and the startup The Hacking Games, which aims to identify talented gamers and redirect them into cybersecurity — for example, into red teaming. There was also a warning about the toxic reality of cybercrime, where personal attacks such as doxing (publishing personal data) and swatting (a false report intended to prompt a police raid) are common.
JokerOTP: another seller of a tool for capturing MFA codes arrested
Dutch police detained a 21-year-old man from Dordrecht, suspected of selling access to the tool JokerOTP. It automated phishing scenarios in which a victim receives a one-time code (OTP) and at the same moment an automated caller posing as customer support calls and tricks the victim into revealing the code. According to police, access was offered via Telegram in the form of license keys.
Investigators say JokerOTP caused at least $10 million in losses over two years and was used in more than 28,000 attacks across 13 countries. The investigation continues, and police say they have already identified additional buyers in the Netherlands who will be prosecuted in due course.
Odkazy:
- https://www.bleepingcomputer.com/news/security/police-arrest-seller-of-jokerotp-mfa-passcode-capturing-tool/
- https://therecord.media/dutch-police-arrest-man-over-jokerotp-password-stealer
AgreeToSteal: the first known malicious Outlook add-in “in the wild”
Researchers described an unusual supply-chain attack in which the legitimate Outlook add-in AgreeTo (last updated in December 2022) was abused after its infrastructure became abandoned and re-claimable. The attacker took over the address/infrastructure pointed to by the add-in's manifest and began serving users a fake Microsoft login page. According to Koi Security, this resulted in the theft of 4,000+ credentials; the data was exfiltrated via the Telegram Bot API and victims were then redirected to the legitimate login to make the attack less noticeable.
Important security detail: the add-in had the ReadWriteItem permission, meaning it could read and modify emails. Researchers therefore warned that besides phishing there was also the potential for far more damaging scenarios, such as silent exfiltration of mailbox content. According to a subsequent update, Microsoft had removed the add-in from the Marketplace by 12 February 2026, and users are advised to remove the add-in and proactively change their password.
Odkazy:
- https://www.koi.ai/blog/agreetosteal-the-first-malicious-outlook-add-in-leads-to-4-000-stolen-credentials
- https://thehackernews.com/2026/02/first-malicious-outlook-add-in-found.html
- https://www.malwarebytes.com/blog/news/2026/02/outlook-add-in-goes-rogue-and-steals-4000-credentials-and-payment-data
BeyondTrust: critical RCE (CVE-2026-1731) and confirmed exploitation
Security teams observed "in-the-wild" activity exploiting the critical vulnerability CVE-2026-1731 (score 9.9) in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) products. The flaw allows unauthenticated remote execution of OS commands (RCE) via specially crafted requests. watchTowr published technical details of the observed exploitation (including abuse of the get_portal_info call and subsequent establishment of a WebSocket channel).
BeyondTrust issued advisory BT26-02 and patches; at the same time, PRA version 25.1+ does not require the patch according to vendor communication (the older branch is vulnerable). CISA subsequently on 13 February 2026 added CVE-2026-1731 to the Known Exploited Vulnerabilities (KEV) catalog, i.e., as an actively exploited vulnerability.
Odkazy:
- https://thehackernews.com/2026/02/researchers-observe-in-wild.html
- https://www.beyondtrust.com/trust-center/security-advisories/bt26-02
- https://www.cisa.gov/news-events/alerts/2026/02/13/cisa-adds-one-known-exploited-vulnerability-catalog
- https://arcticwolf.com/resources/blog/cve-2026-1731/
- https://www.rapid7.com/blog/post/etr-cve-2026-1731-critical-unauthenticated-remote-code-execution-rce-beyondtrust-remote-support-rs-privileged-remote-access-pra/
NÚKIB: reporting under the new cyber law already has 4,825 entities
NÚKIB reported that the new Cybersecurity Act (č. 264/2025 Sb.) and the decree on regulated services (č. 408/2025 Sb.) came into effect on 1 November 2025. Organizations that met the criteria on that date had 60 days to report a regulated service — the deadline ended on 31 December 2025.
By 1 January 2026 the report had been made by "over 4,500" entities, and by 8 February 2026 specifically 4,825. NÚKIB has long stated that roughly 6,000 organizations will fall under the law. The office also reminds that long-term non-compliance can lead to administrative proceedings and fines up to 250 million Kč or up to 2 % of global annual net turnover.
Stanislav Novotný talks more about these events in the new episode of the ALEF SecurityCast:
Other news of the week that didn't make the main roundup
Google is shutting down its dark web monitoring tool
Google announced that it will discontinue its Dark Web Monitoring Tool in February 2026 and will remove associated user data. The service alerted about found personal data on the dark web; the company now wants to focus more on tools providing active protection and security recommendations. Source: https://www.malwarebytes.com/blog/news/2026/02/a-week-in-security-february-9-february-15
Windows 11 update causes boot loop
After installing security update KB5077181 for Windows 11 some users report endless rebooting. The update was meant to address security flaws but in some cases prevented the system from booting correctly. Source: https://cybersecuritynews.com/windows-11-kb5077181-security-update/
Data leak at telecom operator Odido
Dutch operator Odido confirmed a data leak of approximately 6.2 million customers after unauthorized access to a database. Affected information included names, addresses and email contacts; according to the company passwords and login credentials were not compromised. Source: https://www.techradar.com/pro/security/major-telco-breach-sees-6-2-million-users-have-personal-info-leaked-heres-what-we-know-so-far
Incident in mobile device management used by EU institutions
CERT-EU confirmed a security incident affecting a mobile device management platform used by EU institutions. The incident was reportedly quickly contained but shows continued pressure on governmental and supranational IT infrastructure. Source: https://www.helpnetsecurity.com/2026/02/15/week-in-review-exploited-newly-patched-beyondtrust-rce-united-airlines-ciso-on-building-resilience/
New framework for managing risks of autonomous AI agents
UC Berkeley Center for Long-Term Cybersecurity published a framework focused on managing risks associated with autonomous AI agents. The document warns that systems capable of autonomous decision-making may present a new vector of cyber and systemic risks. Source: https://ppc.land/uc-berkeley-unveils-framework-as-ai-agents-threaten-to-outrun-oversight/
Other trends and overviews
Credential-stealing extensions for Chrome and fake e-shops exploiting interest in the 2026 Olympic Games Source: https://www.malwarebytes.com/blog/news/2026/02/a-week-in-security-february-9-february-15
Discussions about the security of industrial and OT systems at conferences S4x26 and BSides ICS/OT Source: https://industrialcyber.co/features/from-concept-to-consequence-how-s4x26-bsides-ics-and-industrial-cyber-days-are-reframing-ot-security/
According to a survey, 58% of Brits faced significant online risk in 2025, with increasing use of generative AI reducing digital trust Source: https://www.techradar.com/pro/security/58-percent-of-brits-faced-significant-online-risk-in-2025-increased-ai-usage-is-reducing-digital-trust
ENISA published a new methodology for cybersecurity exercises for organizations Source: https://www.enisa.europa.eu/