Incomplete Windows Patch Opens Door to Zero-Click Attacks
2026-04-27T13:24:31Z•cc40d9e2a7388f531df06233857cd956fe442ccef6e33c969f907f3f1c96256a
AI prompt injectionAPT28CVE-2026-6770Fast16FirefoxGopherWhisperItron breachOpenSSHPack2TheRootPackageKitSnow malwareTor fingerprintingUNC6692local privilege escalationroot escalationsoutheast asia cyberscamszero-click
What happened
A SecurityWeek feed reports multiple high-impact incidents and vulnerabilities: an incomplete Windows patch has left systems open to zero-click attacks exploited by Russia-linked APT28 against Ukraine and EU targets; a 15‑year OpenSSH certificate parsing flaw can yield a full root shell; a PackageKit race condition dubbed “Pack2TheRoot” allows local privilege escalation to root; Firefox/Tor user‑fingerprinting vulnerability CVE-2026-6770 was patched in Firefox 150 and Tor 15.0.10; UNC6692 is using email‑bombing and social engineering to deploy Snow malware variants for persistence; Itron (an能源
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- cc40d9e2a7388f531df06233857cd956fe442ccef6e33c969f907f3f1c96256a
- Enrichment time
- 2026-04-27T13:24:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.