Weekly review

ThreatNoir Morning Brief — June 18

2026-06-18Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — June 18, 2026

The threat landscape continues to evolve rapidly as critical vulnerabilities emerge across major enterprise platforms and sophisticated malware campaigns target developers and infrastructure. Today's review highlights urgent security concerns spanning from cloud infrastructure to development environments, requiring immediate attention from security teams worldwide.

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

Microsoft has formally disclosed a critical vulnerability in its Malware Protection Engine that affects Microsoft Defender installations globally. The flaw, designated CVE-2026-50656 with a CVSS score of 7.8, represents an elevation of privilege vulnerability that could allow attackers to gain SYSTEM-level access on compromised systems. The company has confirmed that a patch is currently in development and will be released to address this security gap. Source: Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices

A significant data breach dubbed FortiBleed has exposed VPN credentials for approximately 73,932 Fortinet and FortiGate firewall devices belonging to organizations across the globe. The leaked credentials provide direct access to critical network infrastructure, potentially enabling unauthorized remote access to enterprise environments. This exposure underscores the risks posed by unpatched network security appliances and highlights the need for organizations to audit their Fortinet device inventory and credential management practices. Source: FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices

Crypto Clipper Uses Tor and Worm-Like Propagation for Persistence and Control

Microsoft Threat Intelligence has identified an active cryptocurrency clipper campaign that combines multiple attack vectors to establish persistent access and maintain command and control capabilities. The malware, detected as Trojan: Win32/CryptoBandits.A, employs clipboard theft to intercept cryptocurrency transactions, wallet replacement techniques, and Tor-based communications to evade detection. The campaign demonstrates worm-like propagation behavior, enabling the malware to spread laterally through infected systems while establishing a lightweight backdoor for follow-on attacks. This sophisticated approach allows threat actors to maintain long-term access while stealing cryptocurrency assets from victims. Source: Crypto Clipper uses Tor and worm-like propagation for persistence and control

Socket Firewall Now Blocks Malicious VS Code and Open VSX Extensions

The developer supply chain faces renewed threats as attackers continue targeting code editor extension marketplaces to distribute malware. Following a May 2026 incident where a poisoned Nx Console extension compromised GitHub and exposed internal repositories, Socket has extended its Firewall protection to include VS Code Marketplace and Open VSX extensions. The new capability blocks malicious editor extensions before they can install or execute within developer environments, addressing a critical gap where malicious code previously ran undetected once installed. Socket Firewall now provides install-time and update-time enforcement across both major editor extension ecosystems, protecting against threats like the GlassWorm attacks that have repeatedly targeted Open VSX with credential-stealing extensions. The feature is currently available in beta for Socket Enterprise customers. Source: Socket Firewall Now Blocks Malicious VS Code and Open VSX Extensions

Security teams face a critical window to address these emerging threats. The combination of unpatched infrastructure vulnerabilities, exposed credentials, and supply chain attacks targeting developer tools demands immediate action across network, endpoint, and development environments.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Crypto Clipper uses Tor and worm-like propagation for persistence and control
MITRE ATT&CK12
  • Data from Local System (clipboard)
  • OS Credential Dumping (implied by private key theft)
  • Browser Session Hijacking (implied by clipboard theft)
  • Exfiltration Over Alternative Protocol (Tor)
  • Use of VBScript/WSH for execution
  • Use of PowerShell for execution
  • Screen capture
  • Web Protocols (HTTP/HTTPS) for C2
  • Exfiltration Over C2 Channel
  • Registry Run Keys / Startup Folder for persistence
  • Scheduled Task/Job
  • Process Injection (implied by backdoor capability)
Malware1
  • Trojan: Win32/CryptoBandits.A
    Microsoft Defender Antivirus detection name for the crypto clipper.