Security Briefing | July 09, 2026 - Microsoft Finally Patches RoguePlanet Defender Flaw, GodDamn Ransomware Disables Defenses via Kernel Driver, Six AI Coding Tools Vulnerable to GhostApproval Attack
Microsoft has released a patch for CVE-2026-50656 (CVSS 7.8), the RoguePlanet Microsoft Defender privilege escalation flaw first disclosed publicly in June 2026. A new ransomware family called GodDamn uses the PoisonX kernel driver to disable endpoint security software before encrypting, assessed as a Beast ransomware rebrand. Wiz researchers disclosed GhostApproval, a symlink attack affecting six major AI coding assistants including Claude Code, Amazon Q Developer, and Cursor.
By EACA Summit Content Team

1. Microsoft Patches RoguePlanet Defender Flaw Granting SYSTEM Privileges
Microsoft released a security update for CVE-2026-50656 (CVSS 7.8), a privilege escalation vulnerability in the Microsoft Malware Protection Engine (mpengine.dll) dubbed RoguePlanet, first publicly disclosed in June 2026. The patch arrives nearly a month after the vulnerability was made public, closing a window during which attackers could exploit the flaw to gain SYSTEM privileges.
Verified Facts
- CVE-2026-50656 is a privilege escalation vulnerability in Microsoft Malware Protection Engine (mpengine.dll)
- CVSS score is 7.8
- Microsoft released a security update to address the flaw
- Patch issued nearly a month after public disclosure
Evidence
- CVE-2026-50656
- Microsoft Security Update
Impact
Defenders must ensure Microsoft Defender and Malware Protection Engine are updated to prevent local privilege escalation attacks that could lead to full system compromise.
Confidence Level: High
Sources The Hacker News | SecurityWeek
2. GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

A new ransomware family called GodDamn has been observed in the wild since May 21, 2026. It employs the PoisonX kernel driver to neutralize security software before encrypting, evading detection. Symantec's Threat Hunter Team assesses it as a rebrand of the Beast ransomware.
Verified Facts
- GodDamn ransomware first spotted on May 21, 2026
- Uses PoisonX kernel driver to disable security software
- Assessed to be a rebrand of Beast ransomware
Evidence
- Symantec Threat Hunter Team report
Impact
Organizations should monitor for PoisonX driver usage and ensure endpoint detection and response (EDR) solutions can detect kernel-level defense evasion.
Confidence Level: High
Sources The Hacker News | SecurityWeek
3. AI Coding Assistants Vulnerable to GhostApproval Symlink Attacks
Researchers at Wiz disclosed a vulnerability in six popular AI coding assistants that allows a malicious repository to use symlinks to trick the assistant into writing to sensitive files, potentially leading to code execution. The attack, named GhostApproval, exploits the assistant's file approval mechanism and affects Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, and Windsurf.
Verified Facts
- Affected tools: Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity, Windsurf
- Attack uses symlinks to redirect file writes to sensitive locations
- Disclosed by Wiz research team
Evidence
- Wiz research disclosure
Impact
Developers using AI coding assistants should be cautious when approving file modifications and review symlink usage in repositories. Vendors should implement path validation to prevent this class of attack.
Confidence Level: High
Sources The Hacker News | SecurityWeek
Also Noted
A data breach at Japanese telecom KDDI impacted approximately 12 million individuals. This follows the KDDI breach reported June 29 affecting 14.2 million email logins, suggesting a pattern of ongoing security incidents at the organization. Affected individuals should change passwords and enable multi-factor authentication.
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



