Microsoft rolls out revamped Windows Insider Program

2026-04-25T19:23:35Z8ffd3e84389cb3923981f4df8e107ef71d1d3fac91ed99a25593687c57437deb
ASACiscoFTDFirepowerFirestarterMicrosoft TeamsSnow malwareUNC6692arbitrary file uploadbitwardenbreeze-cachecheckmarxcredential theftexploitationlocal privilege escalationmalwarenpm supply-chainpack2therootpackagekitpersistencesocial engineeringsupply-chain compromisewordpressxsszimbra

What happened

BleepingComputer published multiple security and product updates (Apr 23–25, 2026). Major threats: UNC6692 is using Microsoft Teams social engineering to deploy a new 'Snow' malware suite (extension, tunneler, backdoor); 'Firestarter' malware persists on Cisco Firepower/ASA/FTD devices despite patches; a critical arbitrary file upload vulnerability in the Breeze Cache WordPress plugin is being actively exploited; more than 10,000 Zimbra instances are being targeted via an XSS flaw; a local privilege escalation dubbed Pack2TheRoot affects PackageKit allowing root access; the Bitwarden CLI npm发布

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
8ffd3e84389cb3923981f4df8e107ef71d1d3fac91ed99a25593687c57437deb
Enrichment time
2026-04-25T19:23:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft rolls out revamped Windows Insider Program · Baitaphish