Incomplete Windows Patch Opens Door to Zero-Click Attacks

2026-04-27T13:24:31Zcc40d9e2a7388f531df06233857cd956fe442ccef6e33c969f907f3f1c96256a
AI prompt injectionAPT28CVE-2026-6770Fast16FirefoxGopherWhisperItron breachOpenSSHPack2TheRootPackageKitSnow malwareTor fingerprintingUNC6692local privilege escalationroot escalationsoutheast asia cyberscamszero-click

What happened

A SecurityWeek feed reports multiple high-impact incidents and vulnerabilities: an incomplete Windows patch has left systems open to zero-click attacks exploited by Russia-linked APT28 against Ukraine and EU targets; a 15‑year OpenSSH certificate parsing flaw can yield a full root shell; a PackageKit race condition dubbed “Pack2TheRoot” allows local privilege escalation to root; Firefox/Tor user‑fingerprinting vulnerability CVE-2026-6770 was patched in Firefox 150 and Tor 15.0.10; UNC6692 is using email‑bombing and social engineering to deploy Snow malware variants for persistence; Itron (an能源

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
cc40d9e2a7388f531df06233857cd956fe442ccef6e33c969f907f3f1c96256a
Enrichment time
2026-04-27T13:24:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.