EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJULY 9, 20263 min read

Security Briefing | July 09, 2026 - Microsoft Finally Patches RoguePlanet Defender Flaw, GodDamn Ransomware Disables Defenses via Kernel Driver, Six AI Coding Tools Vulnerable to GhostApproval Attack

Microsoft has released a patch for CVE-2026-50656 (CVSS 7.8), the RoguePlanet Microsoft Defender privilege escalation flaw first disclosed publicly in June 2026. A new ransomware family called GodDamn uses the PoisonX kernel driver to disable endpoint security software before encrypting, assessed as a Beast ransomware rebrand. Wiz researchers disclosed GhostApproval, a symlink attack affecting six major AI coding assistants including Claude Code, Amazon Q Developer, and Cursor.

By EACA Summit Content Team

Security Briefing | July 09, 2026 - Microsoft Finally Patches RoguePlanet Defender Flaw, GodDamn Ransomware Disables Defenses via Kernel Driver, Six AI Coding Tools Vulnerable to GhostApproval Attack

1. Microsoft Patches RoguePlanet Defender Flaw Granting SYSTEM Privileges

Microsoft released a security update for CVE-2026-50656 (CVSS 7.8), a privilege escalation vulnerability in the Microsoft Malware Protection Engine (mpengine.dll) dubbed RoguePlanet, first publicly disclosed in June 2026. The patch arrives nearly a month after the vulnerability was made public, closing a window during which attackers could exploit the flaw to gain SYSTEM privileges.

Verified Facts

  • CVE-2026-50656 is a privilege escalation vulnerability in Microsoft Malware Protection Engine (mpengine.dll)
  • CVSS score is 7.8
  • Microsoft released a security update to address the flaw
  • Patch issued nearly a month after public disclosure

Evidence

  • CVE-2026-50656
  • Microsoft Security Update

Impact

Defenders must ensure Microsoft Defender and Malware Protection Engine are updated to prevent local privilege escalation attacks that could lead to full system compromise.

Confidence Level: High

Sources The Hacker News | SecurityWeek

2. GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

Malicious kernel-level driver disabling endpoint detection and response (EDR) protections on a Windows system, illustrating how ransomware operators bypass security software before deploying encryption payloads.

A new ransomware family called GodDamn has been observed in the wild since May 21, 2026. It employs the PoisonX kernel driver to neutralize security software before encrypting, evading detection. Symantec's Threat Hunter Team assesses it as a rebrand of the Beast ransomware.

Verified Facts

  • GodDamn ransomware first spotted on May 21, 2026
  • Uses PoisonX kernel driver to disable security software
  • Assessed to be a rebrand of Beast ransomware

Evidence

  • Symantec Threat Hunter Team report

Impact

Organizations should monitor for PoisonX driver usage and ensure endpoint detection and response (EDR) solutions can detect kernel-level defense evasion.

Confidence Level: High

Sources The Hacker News | SecurityWeek

3. AI Coding Assistants Vulnerable to GhostApproval Symlink Attacks

Researchers at Wiz disclosed a vulnerability in six popular AI coding assistants that allows a malicious repository to use symlinks to trick the assistant into writing to sensitive files, potentially leading to code execution. The attack, named GhostApproval, exploits the assistant's file approval mechanism and affects Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, and Windsurf.

Verified Facts

  • Affected tools: Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, Windsurf
  • Attack uses symlinks to redirect file writes to sensitive locations
  • Disclosed by Wiz research team

Evidence

  • Wiz research disclosure

Impact

Developers using AI coding assistants should be cautious when approving file modifications and review symlink usage in repositories. Vendors should implement path validation to prevent this class of attack.

Confidence Level: High

Sources The Hacker News | SecurityWeek

Also Noted

A data breach at Japanese telecom KDDI impacted approximately 12 million individuals. This follows the KDDI breach reported June 29 affecting 14.2 million email logins, suggesting a pattern of ongoing security incidents at the organization. Affected individuals should change passwords and enable multi-factor authentication.

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings