← Back to News
AI Analysis by The Wire
February 22, 2026 Focus: CYBER Impact: 8/10

Predator Spyware Blinds iOS Privacy Indicators, Microsoft Entra Under Vishing Siege, Hospital Ransomware Shuts Down Mississippi Clinics — Feb 22 Evening Edition

Intellexa's Predator spyware now hooks iOS SpringBoard directly to suppress the green mic and orange camera indicator lights while streaming live audio and video to operators — defeating Apple's core privacy safeguards at the OS layer. Simultaneously, threat actors are running device code phishing campaigns against Microsoft Entra accounts, bypassing MFA by having victims authenticate to attacker-controlled device codes. On the ransomware front, the University of Mississippi Medical Center shut down all clinic locations statewide after an attack, and Japanese semiconductor test equipment giant Advantest confirmed a ransomware hit that may have exposed customer and employee data. The FBI also disclosed that ATM jackpotting attacks surged in 2025, with over $20M stolen via malware forcing cash machines to dispense money. These stories collectively signal that 2026 threat actors are moving up the stack — targeting trust mechanisms, not just data.

Impact Score
8/10
Key Stories
CYBER
Predator Spyware Hooks iOS SpringBoard to Hide Mic and Camera Activity
BleepingComputer — Intellexa's commercial spyware now suppresses iOS green/orange privacy indicators while actively streaming to operators — defeats Apple's most user-visible security signal at the system layer. State-level targeting tool now invisible on fully updated iPhones.
CYBER
Hackers Target Microsoft Entra Accounts in Device Code Vishing Attacks
BleepingComputer — Device code phishing is an increasingly effective MFA bypass — victim authenticates with their real credentials to a code controlled by attacker, handing over valid session tokens. Entra (Azure AD) targeting means enterprise identity infrastructure is in the crosshairs.
CYBER
University of Mississippi Medical Center Shuts All Clinics After Ransomware
BleepingComputer — Healthcare ransomware with operational impact — all statewide clinic locations closed. Patients unable to access care. Signals continued targeting of critical healthcare infrastructure with real-world consequences beyond data theft.
CYBER
Advantest Corporation Hit by Ransomware, Customer Data Potentially Exposed
BleepingComputer — Advantest is a leading semiconductor test equipment manufacturer — their customers are chipmakers. A data breach here could expose semiconductor R&D data, production specs, and supply chain intelligence. Strategic target, not just financial.
CYBER
FBI Warns: $20M Stolen in 2025 ATM Jackpotting Malware Surge
BleepingComputer — ATM jackpotting — malware forcing ATMs to dispense cash — is scaling up. $20M in 2025 represents a significant organized effort. Physical financial infrastructure is being treated as a soft target alongside digital systems.
Analyst Take
The Predator-iOS story is the one to watch. Apple's privacy indicator lights are one of the few hardware-level trust signals users actually notice — when spyware can suppress them at the SpringBoard level, the UI security model is broken for high-value targets. This isn't a CVE you patch, it's a capability gap that requires an iOS update to close. If Intellexa has this, assume similar capability exists in Pegasus and other Tier 1 commercial spyware. The Microsoft Entra device code vishing pattern is equally dangerous for enterprises — it's socially engineered MFA bypass at scale, no malware required. Watch for this TTPs spreading from targeted to widespread use within 60-90 days as toolkits commoditize it. The hospital + semiconductor manufacturer ransomware hits in the same week reinforce a trend: attackers are deliberately targeting high-leverage, operationally critical organizations where downtime pressure maximizes ransom likelihood. Healthcare and semiconductor supply chain are both sectors where paying is often framed internally as cheaper than the alternative. The ATM jackpotting surge rounds out a picture of threat actors simultaneously exploiting digital identity, physical infrastructure, and operational dependencies — this is portfolio diversification of the criminal ecosystem.