CVE-2022-2068, CVE-2026-23414, CVE-2026-23420, CVE-2026-23422, CVE-2026-31536, CVE-2026-31537, CVE-2026-31557, CVE-2026-31565, CVE-2026-31566, CVE-2026-31570, CVE-2026-31589, CVE-2026-31590, CVE-2026-31593, CVE-2026-31599, CVE-2026-31602, CVE-2026-31606, CVE-2026-31608, CVE-2026-31610, CVE-2026-31611, CVE-2026-31612, CVE-2026-31613, CVE-2026-31617, CVE-2026-31618, CVE-2026-31619, CVE-2026-31620, CVE-2026-31621, CVE-2026-31624, CVE-2026-31626, CVE-2026-31627, CVE-2026-31637, CVE-2026-31646, CVE-2026-31651, CVE-2026-31660, CVE-2026-31663, CVE-2026-31667, CVE-2026-31672, CVE-2026-41079, CVE-2026-41677
Get tomorrow's brief in your inbox
Today: UNC6692 deploys custom "Snow" malware suite via Microsoft Teams social engineering, achieving domain controller compromise through email bombing tactics and fake IT helpdesk personas. Microsoft publishes 38 Linux kernel CVEs in ksmbd and SMB Direct implementations. Windows Insider Program gets simplified to two channels (Experimental and Beta) with immediate feature access replacing gradual rollouts.
Threat actor uses Microsoft Teams to deploy new "Snow" malware
UNC6692 uses Microsoft Teams to deliver a custom malware suite called "Snow" that includes a browser extension (SnowBelt), a tunneler (SnowGlaze), and a Python backdoor (SnowBasin). The attacker initiates contact through email bombing, creating urgency by flooding the victim's inbox, then poses as IT helpdesk via Teams to trick users into clicking a link that installs malicious AutoHotkey scripts. SnowBelt executes on a headless Microsoft Edge instance to remain hidden while SnowGlaze establishes WebSocket tunnels and SOCKS proxy operations. Post-compromise, attackers performed internal reconnaissance scanning for SMB and RDP, dumped LSASS memory, used pass-the-hash techniques, and eventually deployed FTK Imager to exfiltrate the Active Directory database along with SYSTEM, SAM, and SECURITY registry hives from domain controllers.
Microsoft rolls out revamped Windows Insider Program
Microsoft restructured the Windows Insider Program to address confusion around channel structure and gradual feature rollouts. The new structure consolidates Dev and Canary into a single "Experimental" channel for testing features that may never ship, while the Beta channel now provides immediate access to all announced features without gradual rollouts. Users in the Experimental channel can manually enable locked features via Windows Settings > Windows Insider Program > Feature flags. Dev Channel users move to Experimental automatically, while Canary 28000 series users move to Experimental (26H1) and Canary 29500 series users move to Experimental (Future Platforms). Beta users transition to the new Beta experience with minor changes.
Linux Kernel: ksmbd and SMB Direct vulnerabilities (CVE-2026-31610, CVE-2026-31537, CVE-2026-31608, CVE-2026-31611, CVE-2026-31612, CVE-2026-31536, CVE-2026-31613)
Microsoft published seven CVEs affecting Linux kernel ksmbd (SMB server) and SMB Direct implementations. Issues include memory leaks (CVE-2026-31610), buffer credit handling (CVE-2026-31537), double-free conditions (CVE-2026-31608), array bound checking (CVE-2026-31611), extended attribute validation (CVE-2026-31612), completion handling (CVE-2026-31536), and out-of-bounds reads in symlink parsing (CVE-2026-31613). All CVEs show minimal EPSS scores (0.000, 4th-10th percentile), indicating low predicted exploitation probability.
TLS, KVM, USB, Network Driver CVEs (CVE-2026-23414, CVE-2026-31593, CVE-2026-31590, CVE-2026-31606, CVE-2026-31646)
Microsoft published additional Linux kernel CVEs covering TLS async handling (CVE-2026-23414), KVM SEV-SNP VMSA synchronization (CVE-2026-31593 and CVE-2026-31590), USB gadget function handling (CVE-2026-31606), and network driver memory management (CVE-2026-31646). All show minimal EPSS scores (0.000, 4th-5th percentile).
Additional Linux kernel CVEs (31 CVEs)
Microsoft published 31 additional Linux kernel CVEs covering ALSA audio drivers, framebuffer drivers, input subsystem, memory management, NVMe, NFC, CAN gateway, USB gadget, network protocols, RDMA, and staging drivers. CVE-2026-31627 (I2C/SMBUS message size checking), CVE-2026-31619 (ALSA fireworks device-supplied status bounds), CVE-2026-41079 (CUPS SNMP heap out-of-bounds read), CVE-2026-31557 (NVMe async event work queue), CVE-2026-31620 (ALSA usx2y NULL deref), CVE-2026-31618 (framebuffer divide-by-zero), CVE-2026-31617 (USB gadget NCM validation), CVE-2026-31589 (memory management folio handling), CVE-2026-31660 (NFC pn533 skb allocation), CVE-2026-31566 (AMD GPU fence handling), CVE-2026-31599 (media vidtv NULL pointer), CVE-2026-31602 (ALSA ctxfi page limit), CVE-2026-31637 (rxrpc ticket handling), CVE-2026-31570 (CAN gateway heap access), CVE-2026-31624 (HID report size), CVE-2026-31651 (MMC vub300 NULL-deref), CVE-2026-23420 (WiFi wlcore locking), CVE-2026-31672 (WiFi rt2x00usb devres), CVE-2026-23422 (dpaa2-switch interrupt storm), CVE-2026-31565 (RDMA irdma deadlock), CVE-2026-31621 (bnge auxiliary device), CVE-2026-31626 (staging rtl8723bs initialization), CVE-2026-31667 (input uinput circular locking), CVE-2026-31663 (xfrm device reference). All show minimal EPSS scores (0.000, 2nd-7th percentile).
OpenSSL c_rehash command injection (CVE-2022-2068)
The c_rehash script in OpenSSL allows command injection. EPSS score of 18.6% (95th percentile) indicates elevated exploitation probability compared to other CVEs published today. This is a 2022 CVE republished by Microsoft.
rust-openssl PEM callback out-of-bounds read (CVE-2026-41677)
Rust OpenSSL bindings contain an out-of-bounds read vulnerability in PEM password callback handling when user callbacks return oversized length values. EPSS score of 0.1% (25th percentile).
Today's threat landscape shows social engineering attacks leveraging trusted enterprise collaboration tools (Microsoft Teams) to bypass traditional email security controls. The UNC6692 campaign demonstrates sophisticated multi-stage malware deployment with advanced evasion techniques including headless browser execution and WebSocket-based C2 tunneling. The volume of Linux kernel CVE publications (38 total) reflects ongoing security hardening of kernel subsystems, particularly SMB implementations, though low EPSS scores suggest these are preventative fixes rather than responses to active exploitation.