← Back to News
AI Analysis by The Wire
February 22, 2026 Focus: CYBER Impact: 9/10

Microsoft Patches 6 Active Zero-Days, Starkiller PhaaS Defeats MFA in Real-Time, Texas Sues TP-Link Over Chinese State Access — Feb 22 Overnight Edition

Microsoft's February Patch Tuesday dropped fixes for 6 zero-days under active exploitation, spanning Windows Shell, MSHTML, Word, Remote Desktop Services, Desktop Window Manager, and VPN services — the breadth signals coordinated pre-patch exploitation across multiple attack surfaces. Simultaneously, a new phishing-as-a-service called Starkiller renders MFA effectively useless by acting as a real-time man-in-the-middle proxy against real login pages, capturing session tokens the moment authentication completes. Texas added legal pressure to the hardware trust problem by suing TP-Link over knowingly marketing routers as secure while Chinese state-backed actors exploited firmware vulnerabilities — the first major state-level action against a Chinese networking vendor on national security grounds. Taken together, three of the core pillars of enterprise security — patching cadence, MFA, and trusted hardware — are under simultaneous, coordinated pressure.

Impact Score
9/10
Key Stories
CYBER
Microsoft February Patch Tuesday: 6 Zero-Days Under Active Exploitation
Krebs on Security — CVE-2026-21510 (Windows Shell click-to-exploit), CVE-2026-21513 (MSHTML bypass), CVE-2026-21514 (Word), CVE-2026-21533 (RDS SYSTEM escalation), CVE-2026-21519 (DWM privilege escalation), CVE-2026-21525 (VPN DoS) — all actively exploited. Six simultaneous zero-days suggests threat actors had pre-patch access across multiple Windows subsystems.
CYBER
Starkiller PhaaS Uses Real-Time Proxy to Capture MFA Tokens and Session Cookies
Krebs on Security / Abnormal AI — Starkiller spins up a headless Chrome container that loads the actual brand login page and acts as transparent proxy. Victim authenticates for real — MFA completes successfully — and attacker captures the live session token. Keylogger, geo-tracking, Telegram alerts, and SaaS-style campaign analytics included. Bypasses all TOTP and push-based MFA designs.
POLICY
Texas Sues TP-Link Over Chinese State Hacking Exposure and Deceptive Security Marketing
BleepingComputer — First major U.S. state-level legal action against a Chinese networking vendor on national security grounds. TP-Link accused of knowingly marketing routers as secure while firmware vulnerabilities allowed Chinese state-backed access. Sets precedent for state AGs acting where federal action stalls.
CYBER
PayPal Data Breach Exposed SSNs and Sensitive PII for 6 Months Due to Software Error
BleepingComputer — Software error in loan application flow exposed Social Security numbers and sensitive PII for roughly six months before detection. Scale of exposure still being assessed. Signals that internal code review failures are now producing breach timelines comparable to APT dwell times.
AI
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
The Hacker News — Anthropic enters the defensive security tooling market directly with Claude Code Security — AI-powered vuln scanning. Positions Anthropic against existing SAST/DAST vendors and signals that foundation model companies are moving down the stack into enterprise security workflows.
Analyst Take
The Starkiller story is the one to watch most closely. The industry spent a decade telling enterprises that MFA was the answer — the threat model was credential stuffing, and MFA stopped it. Starkiller flips that assumption entirely: if the attacker can proxy a live session, MFA never protected you in the first place, it just created a false checkpoint. This is the same architectural problem as the Entra vishing campaign (already covered) but now productized into a turnkey PhaaS. The implication is that session token security — short-lived tokens, device binding, continuous re-authentication — becomes the new baseline, not MFA completion. Watch for enterprise SSO vendors to rush messaging on this. The six Microsoft zero-days are significant for a different reason: the breadth suggests either coordinated nation-state pre-patch research across multiple Windows subsystems, or a very active exploit broker market. Six exploited-in-the-wild zero-days in a single patch cycle is unusual even for Microsoft. The Texas TP-Link suit is the long-game story — it signals that Chinese hardware exposure is moving from executive threat briefings into actual courtrooms, which changes the liability calculus for enterprises still running TP-Link gear in sensitive environments. If this succeeds, expect copycat suits against other Chinese networking vendors and accelerated rip-and-replace timelines in regulated industries.