The Defensive Line Podcast
The Defensive Line Podcast

The Defensive Line Weekly Podcast 006

25 February 2026 22:13 The Defensive Line

Listen to episode

About this episode

Episode 6 of The Defensive Line Weekly examines how attackers are increasingly exploiting legitimate infrastructure to bypass defences: a Russian-aligned threat actor abuses Microsoft’s real authentication pages to harvest SSO credentials, China-nexus espionage actors exploit hardcoded credentials in Dell’s backup platform after eighteen months of silent access, and a financially motivated group uses AI to compromise over 600 FortiGate devices at scale. The episode also covers Google’s first Chrome zero-day of 2026, critical vulnerabilities in widely used VS Code extensions affecting over 128 million downloads, and a new ClickFix variant that uses DNS queries to deliver malware payloads — bypassing the PowerShell monitoring that defenders have hardened against.

Stories Covered

1. Microsoft Entra Device Code Vishing — Storm-2372

A Russian-aligned threat actor (Storm-2372) has been running an active campaign since August 2024, abusing Microsoft’s legitimate device authorisation grant flow to harvest authenticated sessions across SSO-connected applications. Victims are socially engineered via phishing emails and vishing calls into entering device codes on the genuine microsoft.com/devicelogin page — granting attackers access without stealing passwords or bypassing MFA directly.

Source: Microsoft Security Blog

2. Dell RecoverPoint Zero-Day — CVE-2026-22769

CISA added a maximum-severity hardcoded credential vulnerability in Dell RecoverPoint for Virtual Machines to its Known Exploited Vulnerabilities catalogue on 18 February 2026. Suspected China-nexus espionage actors have actively exploited the flaw since at least mid-2024 — an eighteen-month window — deploying custom malware families against backup and disaster recovery infrastructure.

Sources: The Register, SecurityWeek

3. AI-Augmented Threat Actor Compromises FortiGate Devices at Scale

Amazon Threat Intelligence reported a Russian-speaking, financially motivated actor who used commercial generative AI to compromise more than 600 FortiGate devices across 55+ countries between 11 January and 18 February 2026. The attack relied on exposed admin interfaces and weak credentials — no new vulnerability was required. Post-compromise activity included Active Directory credential theft and targeting of Veeam backup infrastructure, consistent with pre-ransomware sequencing.

Source: AWS Security Blog

4. Chrome Zero-Day CVE-2026-2441 Under Active Exploitation

Google released emergency updates on 19 February 2026 for the first Chrome zero-day exploited in attacks in 2026 — a use-after-free vulnerability in Chrome’s CSS implementation discovered by Google’s Threat Analysis Group. CISA added the vulnerability to its Known Exploited Vulnerabilities catalogue. The fix is available in Chrome version 134.0.7323.88 and later, across Windows, macOS, and Linux.

Source: BleepingComputer

5. Critical Vulnerabilities in Popular VS Code Extensions

OX Security reported high to critical vulnerabilities across four popular Visual Studio Code extensions collectively exceeding 128 million downloads — including Live Server (remote file exfiltration), Code Runner (remote code execution), Markdown Preview Enhanced (JavaScript execution), and Microsoft Live Preview (XSS to file exfiltration). Three of the four extensions had unresponsive maintainers despite disclosure in mid-2025.

Source: OX Security

6. ClickFix Attacks Evolve to Use DNS for Payload Delivery

Microsoft and Huntress disclosed a new ClickFix variant using DNS TXT records to deliver malware payloads — the first known use of DNS as a ClickFix delivery channel. The variant uses the legitimate nslookup command instead of PowerShell or mshta, evading security tools that monitor those execution paths. Recent campaigns delivered ModeloRAT, a remote access trojan for Windows.

Sources: BleepingComputer, Dark Reading

Based on The Defensive Line Weekly intelligence summary for 15–22 February 2026. Subscribe at thedefensiveline.substack.com



This is a public episode. If you would like to discuss this with other subscribers or get access to bonus episodes, visit thedefensiveline.substack.com

Want to find AI jobs?

Join thousands of AI professionals finding their next opportunity

We respect your inbox. Unsubscribe at any time.

© 2026 The Defensive Line Podcast. All rights reserved.

Common Questions

Frequently asked questions

Quick answers about how DevFound's AI matching, resumes, and referrals work.

DevFound's AI Copilot ingests your profile, goals, and live job data to deliver curated matches in seconds. Every match includes a resume variant, suggested referrals, and interview prep so you can act immediately. The more feedback you provide, the sharper the Copilot becomes.

AI-led job searches shrink the hours spent sifting through boards and formatting resumes. DevFound pairs automation with your personal outreach, so you reserve energy for interviews and negotiation. Traditional networking still matters, but AI gives you a lift before you even send a message.

Modern AI roles expect comfort with production-grade code, data fluency, and practical ML tooling. The strongest candidates pair deep technical chops with storytelling—translating model impact to product, GTM, and exec partners. Continuous learning keeps you ahead as stacks evolve.

DevFound rewards active seekers. Keep your profile fresh, respond to match quality prompts, and enable alerts so you never miss a role. The AI prioritizes companies and teams that align with your feedback, accelerating both introductions and interview invites.

High-density tech hubs continue to host the deepest AI talent pools, yet distributed teams are catching up fast. Use DevFound filters to hone in on onsite, hybrid, or fully remote roles and watch openings expand across time zones.

DevFound aggregates thousands of remote AI openings and flags the nuances—core hours, async culture, and visa needs—up front. The Copilot also recommends how to position your distributed work experience so hiring managers know you can thrive on a remote team.