Microsoft rolls out revamped Windows Insider Program
2026-04-25T19:23:35Z•8ffd3e84389cb3923981f4df8e107ef71d1d3fac91ed99a25593687c57437deb
ASACiscoFTDFirepowerFirestarterMicrosoft TeamsSnow malwareUNC6692arbitrary file uploadbitwardenbreeze-cachecheckmarxcredential theftexploitationlocal privilege escalationmalwarenpm supply-chainpack2therootpackagekitpersistencesocial engineeringsupply-chain compromisewordpressxsszimbra
What happened
BleepingComputer published multiple security and product updates (Apr 23–25, 2026). Major threats: UNC6692 is using Microsoft Teams social engineering to deploy a new 'Snow' malware suite (extension, tunneler, backdoor); 'Firestarter' malware persists on Cisco Firepower/ASA/FTD devices despite patches; a critical arbitrary file upload vulnerability in the Breeze Cache WordPress plugin is being actively exploited; more than 10,000 Zimbra instances are being targeted via an XSS flaw; a local privilege escalation dubbed Pack2TheRoot affects PackageKit allowing root access; the Bitwarden CLI npm发布
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 8ffd3e84389cb3923981f4df8e107ef71d1d3fac91ed99a25593687c57437deb
- Enrichment time
- 2026-04-25T19:23:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.