Monday, June 29, 2026
Daily digest
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
CVE-2026-55200 is a critical memory corruption flaw (CVSS 9.2) in libssh2 versions up to and including 1.11.1 that allows a malicious or compromised SSH server to execute code on a connecting client with no credentials or user interaction required. A public proof-of-concept exploit is now available, significantly lowering the bar for exploitation. The vulnerability is in the client-side library, meaning any tool or application that uses libssh2 to initiate SSH connections is at risk.
Why it matters: Ansible commonly uses libssh2 (or wrappers over it) for SSH transport against managed nodes — confirm which SSH library your Ansible version and plugins are using and patch or mitigate immediately given the live PoC. Any automation pipeline or script in your environment that opens outbound SSH connections through libssh2 could be compromised by a rogue or already-breached target host.
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
Microsoft identified and removed 119 malicious Edge extensions from its Add-ons store, collectively dubbed 'StegoAd,' which concealed payloads inside image and font files using steganography. The extensions delayed activation for days after installation to evade sandbox detection, then stole credentials and conducted ad fraud. The threat actor behind the campaign has been active since at least 2021.
Why it matters: If your Intune-managed Windows 11 fleet allows user-installed Edge extensions without an allowlist policy, any of these extensions could have reached managed endpoints. Review your Edge browser policy in Intune to enforce extension allowlisting, and audit installed extensions across your fleet — credential theft in a CMMC L2 environment is a direct CUI exposure risk.
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Researchers at JFrog discovered two hijacked npm packages and a cluster of malicious Go packages designed to drop a Python-based information stealer on Windows, Linux, and macOS. The attack abuses VS Code task runner configurations to execute the payload, deliberately avoiding npm lifecycle scripts to bypass npm v12 security hardening. The stealer targets credentials and sensitive data on compromised developer machines.
Why it matters: If your team uses VS Code for Ansible playbook authoring or infrastructure-as-code development, and pulls npm or Go dependencies as part of that workflow, developer workstations are a viable attack vector — compromised developer credentials could pivot directly into your GovCloud or on-prem automation infrastructure.
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
ESET documented 35 distinct spear-phishing campaigns by Russian APT Gamaredon throughout 2025, with activity concentrated in the second half of the year. The group has expanded its malware arsenal and is now abusing legitimate cloud services as part of its attack infrastructure, complicating detection based on domain or IP blocklists. Primary targets remain Ukrainian entities, though the group's TTPs are broadly applicable against Western defense-sector organizations.
Why Post-Quantum Cryptography Starts With Credentials
The article argues that credential security is the most urgent near-term focus for post-quantum cryptography (PQC) migration because adversaries are already harvesting encrypted credential data today for decryption once quantum hardware matures — a 'harvest now, decrypt later' threat. Elliptic curve and RSA protections on credentials are the first assets at risk when quantum capability arrives. Organizations are advised to prioritize PQC-resistant credential storage and transmission ahead of broader cryptographic migration efforts.
Why it matters: CMMC Level 2 organizations handling CUI are increasingly on NIST's radar for PQC readiness; NIST finalized its first PQC standards in 2024 and compliance frameworks are expected to reference them. Credentials protecting GCC High and AWS GovCloud access are high-value harvest targets — this is a planning and roadmap item, not an emergency, but it should be on your radar now.
Data Breach Exposes Up to 14.2 Million Email Logins at Six ISPs
Japanese telecom KDDI Corporation disclosed a breach of an email system shared with five partner ISPs, exposing up to 14.2 million email login credentials. The incident affected email accounts hosted across the six providers. KDDI has notified affected users and is investigating the scope of unauthorized access.