Security Digest - June 25, 2026
Daily security intelligence briefing for infrastructure and endpoint management teams. Consolidated from authoritative research, vendor advisories, and community discussions.
- Generated (UTC): 2026-06-25 16:17:51 +00:00
- Lookback window: 7 days
π Top Research & Advisories
- No high-priority security research detected in this window.
π» AppSec
- Microsoft updates Visual Studio Code with chat cost tracking and multi-agent chats - (Neowin) Monitor developer tool vulnerabilities and supply chain risks.
π‘ Security Ops
-
AWS AiTM Phishing Kit Steals Console Credentials and MFA Codes in Real Time - (CybersecurityNews) Review CA/MFA settings for tightening opportunities.
-
Crowdstrike Falcon Fusion SOAR workflows not firing for real alerts (but Test Mode works)? - (Reddit r/cybersecurity) Review sensor guidance and deployment posture.
π Infrastructure & Endpoint Control
-
Anyone actually running autonomous / AI pentesting in their SDLC? Looking for real-world experience - (Reddit r/cybersecurity) Evaluate update rings and expedite actions if needed.
-
Malicious Chrome Extension Uses Native Messaging Host to Execute PowerShell Commands - (CybersecurityNews) Validate Chrome coverage; update managed package if needed.
-
Malicious Edge extension abuses Native Messaging as bridge to malware - (BleepingComputer) Validate Edge/WebView2 coverage; refresh managed package.
-
Microsoft adds reusable skills and finance data connectors to Copilot in Excel - (Neowin) Review Office update channel health and security baseline compliance.
-
Rufus alternative Ventoy now supports Windows 11βs mandatory update, fixes major boot bug - (Neowin) Validate workstation security baseline and update compliance.
-
Windows 10 quietly gets one more year of support and updates - (Neowin) Validate workstation security baseline and update compliance.
-
Windows 11 KB5095093 update rolls out new Point-in-Time restore feature - (BleepingComputer) Validate workstation security baseline and update compliance.
π©Ή Patch Tuesday & Update Experience
- Anyone actually running autonomous / AI pentesting in their SDLC? Looking for real-world experience - (Reddit r/cybersecurity) I help run engineering at a software company and we're weighing whether to add autonomous (AI-driven) pentesting alongside our existing SAST/DAST/SCA, instead of leaning only on point-in-time manuβ¦
π Quick Links (Watch Items)
- 5 eyes statement - (Reddit r/cybersecurity)
- 25-Year-Old Vulnerability in cURL Used by 30 Billion Devices Finally Patched - (CybersecurityNews)
- Microsoft: 2 ransomware groups hit SharePoint in parallel attacks - (Reddit r/cybersecurity)
- TABPE: A monthly Windows PE baseline dataset for Cyber security researchers - (Reddit r/cybersecurity)
- Anyone actually running autonomous / AI pentesting in their SDLC? Looking for real-world experience - (Reddit r/cybersecurity)
- Got free voucher for Microsoft Certified: Security Operations Analyst Associate - (Reddit r/cybersecurity)
- Take Home that makes sense in the context of LLMs - (Reddit r/cybersecurity)
- red team leaders - good training content? - (Reddit r/cybersecurity)
- Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks - (BleepingComputer)
- CVE-2026-55205 - (CVE.org)