CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (10 July 2026)

Published: Loading…

At a Glance

  • Microsoft patched RoguePlanet, a Defender Malware Protection Engine flaw tracked as CVE-2026-50656 allowing SYSTEM-level privilege escalation.
  • GodDamn ransomware, a Beast rebrand, uses the PoisonX kernel driver to disable endpoint defenses before encrypting files.
  • GhostApproval symlink flaws affect six AI coding assistants, including Claude Code, Cursor, and Windsurf.
  • A compromised @injectivelabs/sdk-ts npm package stole crypto wallet keys and mnemonics across 18 related packages.
  • AssuranceAmerica disclosed a data breach exposing driver's license numbers of 6.9 million customers after a phishing attack.
  • Operation First Light 2026 led to 5,811 arrests and $293 million seized across 97 countries.

Summary

Microsoft released a patch for RoguePlanet, a privilege escalation vulnerability tracked as CVE-2026-50656 in the Microsoft Malware Protection Engine. The flaw allows authenticated attackers to gain SYSTEM-level privileges on Windows 10 and Windows 11 through a race condition exploit.

GodDamn ransomware, a rebrand of the Beast family, uses the PoisonX kernel driver to disable endpoint security before encrypting victim files. Separately, Microsoft Threat Intelligence detailed GigaWiper, a Golang backdoor combining disk-wiping, fake ransomware, and system sabotage capabilities into one implant.

Wiz disclosed GhostApproval, a set of symlink flaws affecting six AI coding assistants including Claude Code, Cursor, and Windsurf. The flaws let malicious repositories redirect file write operations to sensitive locations such as SSH authorized keys files.

A compromised release of the @injectivelabs/sdk-ts npm package stole wallet private keys and mnemonic phrases across 18 related packages. Separately, the nodemon-sudo npm package impersonated the legitimate nodemon tool while bundling a backdoored tslint-conf dependency for remote code execution. A fake Braintree.Net NuGet package also skimmed credit card data and harvested merchant API keys from Braintree integrations.

AssuranceAmerica disclosed a data breach exposing driver's license numbers and personal information of up to 6.9 million customers. Japanese telecom KDDI reported a breach impacting 12 million people after attackers exploited a zero-day in a third-party email system.

Operation First Light 2026 resulted in 5,811 arrests and $293 million in seized assets across 97 countries and territories. The European Union also took Ireland, Spain, France, and the Netherlands to court over delayed implementation of the NIS2 Directive.

Highlights of the Day

Microsoft Patches RoguePlanet Defender Flaw Allowing SYSTEM Privileges

Microsoft released updates for CVE-2026-50656, a privilege escalation vulnerability in the Microsoft Malware Protection Engine mpengine.dll that could allow SYSTEM-level code execution through a race condition. The flaw affected Microsoft Defender Engine version 1.1.26050.11 and was fixed in version 1.1.26060.3008, with Microsoft rating the issue CVSS 7.8 Important. The vulnerability was publicly disclosed and assessed as exploitation more likely, although Microsoft reported no confirmed exploitation at publication time.

GodDamn Ransomware Uses PoisonX Driver to Disable Defences

Symantec identified GodDamn ransomware as a rebrand of Beast ransomware, which previously evolved from the Monster ransomware family linked to the Hyadina threat actor. In a June 2026 attack, operators used AnyDesk for remote access, a NirSoft-based credential theft toolkit, and the PoisonX kernel driver to disable endpoint security before deploying ransomware. The attack encrypted files with the .God8Damn extension in some cases and targeted at least 10 hosts during network propagation.

Source: Symantec

GigaWiper Backdoor Combines Wipers and Ransomware Code

Microsoft Threat Intelligence identified GigaWiper, a Golang-based backdoor first observed in October 2025 that combines command-and-control capabilities with disk wiping, fake ransomware, and system sabotage functions. The malware includes wiping commands derived from FlockWiper and encryption code from Crucio ransomware, generating unsaved keys that prevent file recovery and renaming encrypted files with the .candy extension. GigaWiper uses RabbitMQ and Redis for C2 communication, creates a scheduled task for persistence, and can execute commands for screen capture, credential access, process control, and destructive operations.

Injective SDK Backdoor Steals Crypto Wallet Keys

Socket and StepSecurity identified malicious @injectivelabs/sdk-ts version 1.20.21 containing code that captured mnemonic phrases and private keys through the SDK’s wallet key derivation functions. The compromised npm release was published across 18 @injectivelabs packages, with stolen key material base64-encoded and sent through HTTPS requests to testnet.archival.chain.grpc-web.injective.network. The affected SDK version was available on npm before a clean 1.20.23 release replaced the compromised packages.

GhostApproval Flaws Let AI Agents Bypass File Trust Controls

Wiz identified GhostApproval vulnerabilities affecting six AI coding assistants, where malicious repositories using symbolic links could redirect agent file operations outside the intended workspace. The flaws affected Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, and Windsurf, with some cases allowing writes to sensitive files such as SSH authorised keys. Cursor and AWS assigned CVEs for fixed issues, including CVE-2026-50549 and CVE-2026-12958.

Source: Wiz

Malicious npm Package Hides Remote Code Execution Backdoor

SafeDep identified nodemon-sudo version 3.1.16 as a malicious npm package that impersonates the nodemon process monitor while introducing the backdoored tslint-conf dependency. The tslint-conf package contains code that fetches a second-stage payload from an IPFS gateway and executes it with Node.js require access, enabling remote code execution when the logger functionality is used. Both packages were published on 7 July 2026 by the npm account conodeeth and avoided install scripts, allowing the payload to trigger only during application runtime.

Source: SafeDep

Attackers Use TON Blockchain to Hide Node.js Backdoor

LevelBlue analysed a campaign targeting hospitality users with malicious ZIP files containing LNK shortcuts that launched obfuscated PowerShell commands and deployed a Node.js backdoor. The malware retrieved its command-and-control address through the TON blockchain, used a custom bytecode virtual machine, created Registry Run persistence, and could download and execute additional payloads. LevelBlue identified more than 400 related LNK samples sharing a MachineID value, with C2 infrastructure using domains hosted behind Cloudflare.

Source: LevelBlue

Daily Coverage

Developments
Rogueplanet PatchGoddamn RansomwareGhostapproval FlawInjective Sdk Backdoor
Vulnerabilities
CVE-2026-50656Microsoft Malware Protection Engine - (High)CVE-2026-11405Firmware Us_Ac6V2.0Rtl_V15.03.06.51_Multi_TCVE-2026-28739CVE-2026-25106CVE-2026-33091CVE-2026-12958Language Servers For Aws (High)CVE-2026-50549Cursor < 3.0 (Critical)CVE-2026-60104Server (High)CVE-2026-59939Httplib2 < 0.32.0 (High)CVE-2026-1207Django 6.0 (Medium)