CVE-2026-26119
Get tomorrow's brief in your inbox
Today: Microsoft patched CVE-2026-26119, an elevation of privilege flaw in Windows Admin Center caused by improper authentication. ClickFix social engineering campaigns now abuse DNS lookup commands to deliver ModeloRAT. A supply chain attack embeds Keenadu malware directly into Android device firmware at the build phase.
Windows Admin Center Elevation of Privilege (CVE-2026-26119)
Microsoft disclosed CVE-2026-26119, an improper authentication vulnerability in Windows Admin Center that allows an authorized attacker to elevate privileges over a network. No CVSS score or EPSS data is available yet.
Apple Tests End-to-End Encrypted RCS Messaging in iOS 26.4 Developer Beta
Apple released iOS and iPadOS 26.4 beta with end-to-end encryption for RCS messages, built on the MLS protocol via RCS Universal Profile 3.0. E2EE is currently limited to Apple-to-Apple conversations. The beta also enables full Memory Integrity Enforcement (MIE) mode for apps and will make Stolen Device Protection the default for all iPhones, adding biometric authentication and a one-hour delay for sensitive account changes when away from familiar locations.
Supply Chain Attack Embeds Keenadu Malware in Android Device Firmware
A supply chain attack embeds malware called Keenadu directly into Android device firmware during manufacturing. Once active, Keenadu downloads payloads that hijack browser searches, commit ad fraud, and execute additional actions without user knowledge. Devices compromised at the firmware level cannot be cleaned through standard app removal or factory resets.
ClickFix Attacks Abuse DNS Lookup Commands to Deliver ModeloRAT
ClickFix social engineering campaigns have evolved with a new technique that abuses DNS lookup commands (nslookup) to trick users into infecting their own machines with ModeloRAT. The attack bypasses traditional download-based detection by using a legitimate system utility as the delivery mechanism.
Ireland Opens GDPR Investigation into X's Grok AI
Ireland's Data Protection Commission launched a formal GDPR investigation into X over Grok AI's ability to generate non-consensual sexual images of real people, including children. As the lead EU supervisory authority for X, the DPC's findings could result in fines enforceable across all 27 EU member states and three EEA countries. This joins existing investigations by the UK ICO, the European Commission, California AG, UK Ofcom, and French prosecutors who raided X's Paris offices and summoned Elon Musk for April interviews.
Two themes stand out today: social engineering is getting more creative, and supply chain compromise continues to move deeper into hardware. ClickFix campaigns now weaponize built-in system tools like nslookup rather than relying on traditional malware downloads, making detection harder with standard controls. Keenadu's firmware-level embedding during manufacturing represents the most persistent form of supply chain attack, one that survives factory resets and requires full device replacement.