Thursday, July 9, 2026
Daily digest
Microsoft Patches RoguePlanet Defender Zero-Day Granting SYSTEM Privileges
Microsoft released an out-of-band patch for CVE-2026-50656 (CVSS 7.8), a privilege escalation flaw in the Malware Protection Engine (mpengine.dll) dubbed RoguePlanet. The vulnerability was publicly disclosed after June 2026 Patch Tuesday, meaning details were available before a fix existed. A local attacker exploiting the flaw can gain SYSTEM-level privileges on an affected Windows endpoint.
Why it matters: Your Intune-managed Windows 11 fleet runs Defender as the primary AV engine — verify the mpengine.dll update has deployed to all endpoints and confirm Intune compliance policies reflect the patched signature/engine version.
GodDamn Ransomware Uses BYOVD via PoisonX Driver to Kill Endpoint Defenses
A new ransomware family called GodDamn, assessed to be a Beast ransomware rebrand, uses a Microsoft-signed malicious kernel driver called PoisonX in a Bring Your Own Vulnerable Driver (BYOVD) attack to disable security software before encrypting files. Symantec's Threat Hunter Team first spotted it in the wild on May 21, 2026, with U.S. companies among the targets. The signed driver allows the malware to operate at kernel level, bypassing endpoint defenses.
Why it matters: BYOVD attacks succeed even against well-patched endpoints by abusing kernel trust — confirm your Defender for Endpoint (or equivalent) has Attack Surface Reduction rules and vulnerable driver blocklist enforcement enabled, and review whether your Nutanix AHV VMs running Windows workloads have kernel-level driver restrictions in place.
Ubiquiti Patches Critical UniFi Flaws Including a CVSS 10.0 Access Control Bug
Ubiquiti shipped updates addressing multiple critical vulnerabilities across UniFi Connect, Talk, Access, Protect, and OS product lines. The most severe, CVE-2026-50746, carries a CVSS score of 10.0 and is an improper access control flaw in the UniFi Connect Application that could allow privilege escalation and arbitrary command execution. Additional flaws affect the broader UniFi ecosystem.
Why it matters: If UniFi gear is in scope for your CMMC L2 boundary — particularly UniFi Access for physical access control or UniFi Protect for cameras — a CVSS 10.0 unauthenticated command execution flaw is an immediate patching priority that also has implications for NIST 800-171 SI-2 and CM-6.
Entra Passkey Enrollment Vishing Campaign Targets Microsoft 365 Users
A threat actor is conducting voice phishing (vishing) attacks against Microsoft 365 users, impersonating IT security staff and convincing targets to enroll an attacker-controlled passkey into their Entra ID account. Once enrolled, the passkey gives the attacker persistent, phishing-resistant authentication to the victim's M365 account. Multiple sectors have been targeted.
Why it matters: Your M365 GCC High environment uses Entra ID — audit passkey registration events in Entra sign-in logs, ensure Conditional Access policies require admin approval or number matching for new FIDO2/passkey registrations, and brief your help desk on this specific social engineering script.
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
A single threat actor leveraged AI-assisted workflows, chained cloud misconfigurations, and stolen credentials to fully compromise a large AWS customer's cloud environment within 72 hours and then extort the victim. The attacker used AI tools to accelerate reconnaissance, privilege escalation, and lateral movement steps that would traditionally take days or weeks. Dark Reading's report details the attack chain.
Why it matters: Your AWS GovCloud footprint faces the same chained-misconfiguration risk — review IAM least-privilege posture, ensure CloudTrail alerting thresholds are tuned for AI-speed enumeration, and validate that GuardDuty is active across all GovCloud accounts.
China-Linked Hackers Exploit Roundcube Flaw to Spy on University Mail Servers
A China-linked threat cluster (tracked by Proofpoint) has been exploiting vulnerable Roundcube webmail servers at U.S. and Canadian universities to steal credentials and deploy backdoor malware. Proofpoint estimates a few dozen institutions were targeted. The attackers used the access to conduct espionage against academic researchers.
GhostApproval: Symlink Flaws in Six AI Coding Agents Allow Malicious Repos to Hijack Developer Machines
Wiz researchers found a symlink-based vulnerability, dubbed GhostApproval, affecting six AI coding assistants: Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. A booby-trapped repository can cause the assistant to request permission to edit a harmless-looking file while the write is silently redirected to a sensitive system file. The attack enables arbitrary file writes on the developer's machine without triggering obvious permission prompts.
Why it matters: If developers in your environment use Amazon Q Developer (likely given AWS GovCloud usage) or any of the other affected agents against internal or third-party code repos, they are exposed to this attack — check vendor patch status for each tool and consider sandboxing AI coding agents from sensitive file paths until fixes are confirmed.
GitHub 'Verified' Commit Signatures Can Be Forged Without the Signing Key
Researchers demonstrated that Git's SHA-1-based commit hashing allows an attacker without the signing key to craft a second commit with identical files, author, date, and a valid GPG signature that GitHub still marks as 'Verified.' The original and forged commits have different hashes, but everything a human reviewer checks — author, signature status, contents — appears identical. This undermines supply-chain integrity checks that rely on GitHub's Verified badge.
Why it matters: If your Ansible playbooks, infrastructure-as-code, or other pipeline artifacts are pulled from GitHub repos where commit signing is treated as an integrity control, this finding means that control is weaker than assumed — consider supplementing with artifact signing (e.g., Sigstore/cosign) or hash pinning outside Git's commit namespace.
NIST's National Vulnerability Database Faces Structural Backlog Crisis
A new report warns that NIST's NVD backlog of unanalyzed CVEs will persist indefinitely unless NIST makes significant structural changes to how it processes vulnerability submissions. The backlog has been growing since early 2024 and affects the completeness and timeliness of CVSS scores, CPE data, and enrichment that downstream vulnerability management tools depend on. Experts say the current resourcing model is insufficient.
Why it matters: CMMC L2 and NIST 800-171 SI-2 require timely flaw remediation based on risk — if your vulnerability scanner relies on NVD enrichment for CVSS scores and affected CPEs, gaps in NVD data could cause high-severity CVEs to appear unscored or miscategorized, distorting your patching prioritization queue.
AWS Security Blog: Designing Against System Prompt Leakage in Generative AI Applications
AWS published a technical post covering architectural mitigations for system prompt leakage in LLM-based applications, a class of vulnerability where an attacker extracts the confidential instructions and context embedded in an AI application's system prompt. The post covers threat modeling, prompt isolation patterns, and defense-in-depth strategies for production AI workloads. It is oriented toward teams building or operating generative AI on AWS.
Why it matters: If your self-hosted AI stack or any AWS GovCloud-hosted LLM application uses system prompts containing CUI-adjacent information (security policies, data handling rules, internal tool descriptions), prompt leakage is a data spillage risk relevant to CMMC L2 — this post provides actionable architectural guidance.
Senate Lawmaker Presses DoD and Tech Firms to Disclose AI Contract Terms
Sen. Elizabeth Warren sent letters to the Department of Defense and major AI vendors demanding full disclosure of contract terms governing AI tools deployed in defense contexts, citing an inability to assess what safeguards exist without seeing the complete agreements. The inquiry focuses on accountability gaps when commercial AI is integrated into DoD workflows. This follows a pattern of congressional scrutiny of AI procurement transparency.
Allstate Quits Broadcom, Alleges Retaliatory License Audit on the Way Out
Allstate Insurance has severed its Broadcom relationship and alleges that Broadcom initiated a retaliatory software license audit after Allstate announced its intent to migrate off VMware and CA Technologies products. Broadcom is now pursuing both CA and VMware-related lawsuits against the insurer. The case is the highest-profile public example yet of post-acquisition Broadcom licensing disputes turning litigious.
Why it matters: If your organization is on Nutanix AHV as a VMware alternative or is mid-migration, this case illustrates the legal exposure that can accompany a Broadcom exit — ensure your license compliance documentation is airtight before or during any migration notice to Broadcom.