- Nuance PowerScribe Remote Code Execution Vulnerability
- Windows BitLocker Security Feature Bypass Vulnerability
- Microsoft Office Remote Code Execution Vulnerability
- Microsoft Office Remote Code Execution Vulnerability
- Microsoft Office Remote Code Execution Vulnerability
- Microsoft Office Remote Code Execution Vulnerability
- HTTP.sys Denial of Service Vulnerability
- Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
ThreatNoir Morning Brief — June 10
Morning Review in IT Security — June 10, 2026
The threat landscape continues to shift rapidly as security researchers expose critical vulnerabilities across major software platforms. Today's review covers emerging zero-day exploits in Microsoft Defender, a comprehensive Patch Tuesday analysis, supply chain compromises affecting open-source projects, and nation-state attacks targeting Ukrainian organizations through unpatched vulnerabilities.
Microsoft Defender 'RoguePlanet' Zero-Day Grants SYSTEM Privileges
A critical zero-day vulnerability has been identified in Microsoft Defender that enables attackers to escalate privileges to SYSTEM level. Tracked as 'RoguePlanet', this vulnerability represents a significant security risk for organizations relying on Microsoft's built-in security solutions. The flaw allows threat actors to bypass security controls and gain complete system access. Source: Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
Microsoft and Adobe Patch Tuesday, June 2026 Security Update Review
Microsoft's June 2026 Patch Tuesday addresses a substantial number of vulnerabilities across its product portfolio. The release includes patches for 206 vulnerabilities, with 33 classified as critical severity and 167 as important severity. Among these updates, Microsoft has addressed three publicly disclosed zero-day vulnerabilities that posed immediate risk to enterprise environments. Additionally, the company resolved 360 Microsoft Edge vulnerabilities, underscoring the ongoing security challenges in browser-based attack surfaces. Organizations should prioritize deployment of these patches to mitigate exposure to active threats. Source: Microsoft and Adobe Patch Tuesday, June 2026 Security Update Review
Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
Microsoft has begun restoring GitHub repositories following a significant supply chain attack that compromised 73 of its open-source projects. The incident involved injection of information stealer malware, including variants such as Hades, Miasma, and Mini Shai-Hulud, into the affected codebases. While Microsoft has restored some repositories as part of its investigation, others remain offline as the company continues its security probe. The company stated that protecting customers and the broader ecosystem remains its priority during this incident response. Source: Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues
Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
Russian threat actors are actively exploiting CVE-2025-8088, a WinRAR vulnerability that was patched in July 2025, against military and government targets in Ukraine. Two separate campaigns have been identified conducting data theft and cyberespionage operations using this flaw. Despite the availability of patches for nearly a year, the continued exploitation of this vulnerability demonstrates the persistent risk posed by unpatched systems in critical infrastructure environments. Source: Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
Today's threat intelligence underscores the importance of rapid patch deployment, vigilant supply chain monitoring, and comprehensive vulnerability management across all organizational systems and dependencies.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- MiasmaName of the ongoing software supply chain campaign
- Mini Shai-HuludRelated malware wave
- HadesRelated malware wave
- information stealerType of malware injected into projects
- WinRAR path traversal vulnerability exploited in Russian campaigns against Ukraine