View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Critical libssh2 flaw lets malicious SSH servers hijack clients

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer β€” The Hacker News Researchers uncovered two hijacked npm packages and multiple Go packages that deploy a Python-based infostealer on Windows, Linux, and macOS. The attack bypasses common npm lifecycle scripts, likely to evade npm v12 security hardenings, indicating a sophisticated supply chain compromise targeting developer ecosystems.
  • Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts β€” The Hacker News Microsoft took down 119 malicious Edge extensions linked to a single threat actor active since 2021. The extensions used steganography (payloads hidden in images/fonts) to activate days after install, stealing credentials and running ad fraud campaigns. This long-running operation highlights the evolving use of stego techniques in browser extension malware.

πŸ”“ VULNERABILITIES & CVEs

  • Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw β€” The Hacker News A critical memory corruption flaw (CVE-2026-55200, CVSS 9.2) in libssh2 client library allows malicious or compromised SSH servers to trigger code execution on connecting clients without user interaction or credentials. All versions up to 1.11.1 are affected. Public PoC is now available, increasing exploitation risk.

πŸ•΅οΈ THREAT RESEARCH & DEEP DIVES

πŸš€ PRODUCT LAUNCHES & UPDATES

  • OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI β€” SecurityWeek OpenAI launched GPT-5.6 Sol, a cybersecurity-focused AI model that matches competitors like Mythos Preview but uses only a third of the output tokens. This efficiency gain promises enhanced AI-driven detection and response capabilities for security teams.

πŸ“° LESSER-KNOWN / UNDER-REPORTED

  • US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve β€” SecurityWeek The US government announced a $10M bounty targeting Russian state-sponsored hackers UNC5792 and UNC4221, who have been actively attacking US officials and military personnel via evolving messaging app exploits. This bounty underscores the ongoing geopolitical cyber conflict and prioritizes disrupting these threat actors.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check