- Microsoft Defender privilege escalation zero-day
ThreatNoir Morning Brief — June 18
Morning Review in IT Security — June 18, 2026
The threat landscape continues to evolve rapidly as critical vulnerabilities emerge across major enterprise platforms and sophisticated malware campaigns target developers and infrastructure. Today's review highlights urgent security concerns spanning from cloud infrastructure to development environments, requiring immediate attention from security teams worldwide.
Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
Microsoft has formally disclosed a critical vulnerability in its Malware Protection Engine that affects Microsoft Defender installations globally. The flaw, designated CVE-2026-50656 with a CVSS score of 7.8, represents an elevation of privilege vulnerability that could allow attackers to gain SYSTEM-level access on compromised systems. The company has confirmed that a patch is currently in development and will be released to address this security gap. Source: Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development
FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices
A significant data breach dubbed FortiBleed has exposed VPN credentials for approximately 73,932 Fortinet and FortiGate firewall devices belonging to organizations across the globe. The leaked credentials provide direct access to critical network infrastructure, potentially enabling unauthorized remote access to enterprise environments. This exposure underscores the risks posed by unpatched network security appliances and highlights the need for organizations to audit their Fortinet device inventory and credential management practices. Source: FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices
Crypto Clipper Uses Tor and Worm-Like Propagation for Persistence and Control
Microsoft Threat Intelligence has identified an active cryptocurrency clipper campaign that combines multiple attack vectors to establish persistent access and maintain command and control capabilities. The malware, detected as Trojan: Win32/CryptoBandits.A, employs clipboard theft to intercept cryptocurrency transactions, wallet replacement techniques, and Tor-based communications to evade detection. The campaign demonstrates worm-like propagation behavior, enabling the malware to spread laterally through infected systems while establishing a lightweight backdoor for follow-on attacks. This sophisticated approach allows threat actors to maintain long-term access while stealing cryptocurrency assets from victims. Source: Crypto Clipper uses Tor and worm-like propagation for persistence and control
Socket Firewall Now Blocks Malicious VS Code and Open VSX Extensions
The developer supply chain faces renewed threats as attackers continue targeting code editor extension marketplaces to distribute malware. Following a May 2026 incident where a poisoned Nx Console extension compromised GitHub and exposed internal repositories, Socket has extended its Firewall protection to include VS Code Marketplace and Open VSX extensions. The new capability blocks malicious editor extensions before they can install or execute within developer environments, addressing a critical gap where malicious code previously ran undetected once installed. Socket Firewall now provides install-time and update-time enforcement across both major editor extension ecosystems, protecting against threats like the GlassWorm attacks that have repeatedly targeted Open VSX with credential-stealing extensions. The feature is currently available in beta for Socket Enterprise customers. Source: Socket Firewall Now Blocks Malicious VS Code and Open VSX Extensions
Security teams face a critical window to address these emerging threats. The combination of unpatched infrastructure vulnerabilities, exposed credentials, and supply chain attacks targeting developer tools demands immediate action across network, endpoint, and development environments.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- FortiBleedName of the data leak and associated operation.
- Data from Local System (clipboard)
- OS Credential Dumping (implied by private key theft)
- Browser Session Hijacking (implied by clipboard theft)
- Exfiltration Over Alternative Protocol (Tor)
- Use of VBScript/WSH for execution
- Use of PowerShell for execution
- Screen capture
- Web Protocols (HTTP/HTTPS) for C2
- Exfiltration Over C2 Channel
- Registry Run Keys / Startup Folder for persistence
- Scheduled Task/Job
- Process Injection (implied by backdoor capability)
- Trojan: Win32/CryptoBandits.AMicrosoft Defender Antivirus detection name for the crypto clipper.
- Nx Console 18.95.0Malicious VS Code extension used in a GitHub breach.