Byer-Nichols Threat Brief for February 1-15 2026
In early February, APT activity leaned hard on cloud abuse, identity compromise, and long‑dwell access, with UNC3886 standing out for its persistence. Exploited bugs across Notepad++, SolarWinds, Apple, and Microsoft underscored the need for fast patching and tighter identity controls. Ransomware crews stayed active, with Qilin and The Gentlemen driving most cases while Cl0p’s earlier huge Cleo‑linked victim dump kept pressure high despite fewer new hits.