July 10, 2026
Valkyrie-bot deployed a WHQL-signed kernel rootkit (WindowsService.sys) operating as a device filter driver with ring0 memory-access capabilities, evading endpoint detection through novel persistence primitives. GodDamn ransomware, a rebrand of Beast, uses the PoisonX Microsoft-signed kernel driver to neutralize EDR in attacks against US companies, continuing BYOVD abuse tactics. Microsoft patched RoguePlanet (CVE-2026-50656), a privilege-escalation flaw in Defender's mpengine.dll that grants SYSTEM access, after a researcher published a PoC following June Patch Tuesday. A pre-auth remote-code execution zero-day in OpenWRT (claimed CVSS 9.6) was disclosed affecting routers; the same vulnerability technique also impacts Horde, Django, WordPress, GitLab, and Dropbear.
July 1, 2026
watchTowr Labs disclosed CVE-2026-8451, a pre-auth memory overread in Citrix NetScaler SAML handling that extends the CitrixBleed lineage, alongside five other patched flaws. A China-linked USB implant infected Japanese military networks for nearly a year via disaster-relief supply chains, while European defense targets faced spear-phishing campaigns abusing AWS Cognito for credential-less C2 infrastructure. Multiple AI agent safety bypasses emerged, including GuardFall (shell injection against coding agents), BioShocking (prompt injection stealing credentials), and poisoned MCP tool descriptions enabling data exfiltration without raising alerts.
June 26, 2026
Gaslight, a Rust-based macOS stealer, is the first malware documented to embed prompt-injection payloads designed to sabotage AI-assisted malware analysis. ESET published a detailed breakdown of Gamaredon's 2025 arsenal, revealing six new PowerShell downloaders and extensive infrastructure laundering targeting Ukrainian government and military entities. Multiple critical vulnerabilities are being actively exploited, including CVE-2025-52465 in GeoServer for credential theft and CVE-2026-8461 in FFmpeg for remote code execution. curl patched a 24-year-old credential-leak vulnerability (CVE-2026-9079) alongside four additional flaws affecting SSH, STARTTLS, and proxy authentication.
June 24, 2026
Critical vulnerabilities hit domain controllers as CVE-2026-41089 (Netlogon RCE) and Onelogon (Zerologon bypass) emerge, while FortiBleed credential-harvesting campaign reaches Finnish organizations after compromising 110M+ credentials from 430K+ Fortinet devices. Major supply-chain threats include Klue OAuth attacks affecting LastPass, malicious npm packages impersonating PostCSS, and Cordyceps malicious pull requests targeting Azure/Google/Apache projects; Anthropic's Mythos model discovered Squidbleed (Heartbleed-style flaw in Squid) and vulnerabilities in classified US systems.
June 21, 2026
Fortinet networks face massive credential exposure via FortiBleed affecting 86,644 devices, while North Korea's Sapphire Sleet compromised 145 Mastra npm packages with an infostealer, and Google Cloud Vertex AI SDK suffered a cross-tenant RCE vulnerability. Critical CVEs in Splunk, NGINX, Cisco SD-WAN, and Joomla are under active exploitation, alongside emerging AI-focused attacks including AutoJack and malicious JetBrains plugins stealing API keys.
June 18, 2026
A critical vulnerability blitz dominates this digest: Oracle PeopleSoft CVE-2026-35273, Splunk CVE-2026-20253, and an unpatched Microsoft Defender RoguePlanet zero-day are actively exploited, with ShinyHunters and other threat actors targeting higher education and enterprise networks. The AI/security layer has emerged as a major attack surface, exemplified by Microsoft 365 Copilot SearchLeak (one-click data exfiltration), Google Vertex AI cross-tenant RCE, and the Novo Nordisk breach that exposed proprietary AI model checkpoints and training infrastructure as ransomware extortion payload—underscoring that AI IP is now a strategic target.