daily cyber × ai intelligence

index

tagged

[libssh2]

2 editions · 1 item

June 29, 2026

  • CVE-2026-55200 in libssh2 now has a public PoC. The critical flaw (CVSS 4.0 score 9.2) lets a malicious or compromised SSH server trigger memory corruption — and possibly code execution — on a connecting client with no credentials or interaction. It affects all releases up to and including 1.11.1; note this is a client-side library, so the exposure is anything that dials out over SSH using libssh2. (The Hacker News) · Vulnerabilities & Exploits

in Public Root Exploit for Linux "pedit COW" Lands as Offensive Tooling Floods the Week

June 25, 2026

Cisco SD-WAN Manager Zero-Day Gives Root via a Malicious CSV as Operation Endgame Smashes Amadey and StealC

Cisco Catalyst SD-WAN Manager zero-day CVE-2026-20245 allows attackers to escalate from admin accounts to root by uploading malicious CSV files, as disclosed by Mandiant. Microsoft and Europol disrupted the shared infrastructure behind Amadey and StealC infostealers in Operation Endgame, recovering ~27M credentials and seizing over $47M. Anthropic alleges Alibaba illicitly extracted capabilities from Claude, highlighting emerging model-distillation IP-theft disputes. A stealthy Mistic RAT serves as entry point for initial-access broker Woodgnat (aka KongTuke), feeding multiple ransomware families including Qilin, Interlock, and Black Basta.