π¨ ACTIVE EXPLOITS & INCIDENTS
- Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer β The Hacker News Researchers uncovered two hijacked npm packages and multiple Go packages that deploy a Python-based infostealer on Windows, Linux, and macOS. The attack bypasses common npm lifecycle scripts, likely to evade npm v12 security hardenings, indicating a sophisticated supply chain compromise targeting developer ecosystems.
- Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts β The Hacker News Microsoft took down 119 malicious Edge extensions linked to a single threat actor active since 2021. The extensions used steganography (payloads hidden in images/fonts) to activate days after install, stealing credentials and running ad fraud campaigns. This long-running operation highlights the evolving use of stego techniques in browser extension malware.
π VULNERABILITIES & CVEs
- Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw β The Hacker News A critical memory corruption flaw (CVE-2026-55200, CVSS 9.2) in libssh2 client library allows malicious or compromised SSH servers to trigger code execution on connecting clients without user interaction or credentials. All versions up to 1.11.1 are affected. Public PoC is now available, increasing exploitation risk.
π΅οΈ THREAT RESEARCH & DEEP DIVES
- The Gentlemen are knocking: custom backdoors and evolving tactics β Securelist (Kaspersky) Kaspersky researchers detail new TTPs and custom backdoors used by The Gentlemen RaaS group, including a newly discovered ransomware variant. The report highlights the groupβs evolution and expanding capabilities, underscoring the need for updated detection strategies against this RaaS actor.
- From mythos to reality: Why the 2026 state of pentesting report proves the need for programmatic defenses β Cybersecurity Dive The 2026 pentesting report emphasizes AIβs ability to discover zero-days within minutes, urging security teams to shift from reactive to programmatic, automated defenses. This signals a critical inflection point in vulnerability management and penetration testing methodologies.
π PRODUCT LAUNCHES & UPDATES
- OpenAI Unveils GPT-5.6 Sol as Its Most Advanced Cybersecurity AI β SecurityWeek OpenAI launched GPT-5.6 Sol, a cybersecurity-focused AI model that matches competitors like Mythos Preview but uses only a third of the output tokens. This efficiency gain promises enhanced AI-driven detection and response capabilities for security teams.
π° LESSER-KNOWN / UNDER-REPORTED
- US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve β SecurityWeek The US government announced a $10M bounty targeting Russian state-sponsored hackers UNC5792 and UNC4221, who have been actively attacking US officials and military personnel via evolving messaging app exploits. This bounty underscores the ongoing geopolitical cyber conflict and prioritizes disrupting these threat actors.