EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJULY 10, 20263 min read

Security Briefing | July 10, 2026 - Unpatched XQUIC DoS Flaw, GigaWiper Combines Wiper and Ransomware, Vishing Campaign Targets Microsoft 365 Passkey Enrollment

An unpatched denial-of-service vulnerability in Alibaba's XQUIC library (XRING) allows any remote client to crash HTTP/3 servers with just 260 bytes of legitimate traffic. Microsoft analyzed GigaWiper, a destructive Windows backdoor combining disk wiping, multi-pass wiping, and fake ransomware into one platform. Okta warns of vishing attacks by threat actor O-UNC-066 tricking Microsoft 365 users into enrolling fake Entra passkeys.

By EACA Summit Content Team

Security Briefing | July 10, 2026 - Unpatched XQUIC DoS Flaw, GigaWiper Combines Wiper and Ransomware, Vishing Campaign Targets Microsoft 365 Passkey Enrollment

1. Unpatched XRING Flaw in XQUIC Enables Remote Server Crashes

A vulnerability in Alibaba's XQUIC library, dubbed XRING, allows any remote client to crash HTTP/3 servers by sending approximately 260 bytes of legitimate QPACK traffic. The flaw, disclosed by FoxIO researcher Sébastien Féry on July 8, 2026, requires no authentication or malformed packets. No patch is currently available.

Verified Facts

  • The XRING flaw exists in XQUIC, Alibaba's QUIC and HTTP/3 library
  • A remote client can crash the server with a short burst of legal traffic
  • The vulnerability was disclosed on July 8, 2026, by FoxIO researcher Sébastien Féry
  • No patch has been released as of July 10, 2026

Evidence

  • The Hacker News article dated July 10, 2026
  • SecurityWeek article referencing the same disclosure

Impact

Organizations using XQUIC-based HTTP/3 services are at risk of denial-of-service attacks. Defenders should monitor for patches and consider temporary mitigations such as rate limiting or disabling HTTP/3.

Confidence Level: High

Sources The Hacker News | SecurityWeek

2. GigaWiper Backdoor Combines Wiping, Ransomware, and Spyware Capabilities

Illustration of destructive malware wiping enterprise storage and permanently erasing critical data, representing a sophisticated backdoor capable of destroying systems while maintaining unauthorized access.

Microsoft analyzed a destructive Windows backdoor called GigaWiper, which bundles three older malware families into a single platform. The backdoor offers operators commands to wipe disks, overwrite the Windows drive, or execute fake ransomware that scrambles files without a recoverable key.

Verified Facts

  • GigaWiper is a Windows backdoor that combines multiple destructive tools
  • It includes a standalone wiper, a multi-pass wiping command, and fake ransomware encryption
  • Microsoft published a detailed analysis on July 9, 2026

Evidence

  • Microsoft Security Blog post dated July 9, 2026
  • SecurityWeek article dated July 10, 2026

Impact

This backdoor poses a significant threat to Windows systems, as it can cause irreversible data loss. Defenders should ensure endpoint detection and response (EDR) systems are updated to detect GigaWiper components.

Confidence Level: High

Sources Microsoft Security Blog | SecurityWeek

3. Okta Warns of Vishing Attacks Targeting Microsoft 365 Passkey Enrollment

A threat actor tracked as O-UNC-066 is using voice-based phishing (vishing) to trick Microsoft 365 users into enrolling a fake Entra passkey. The attack leverages a panel-controlled phishing kit that mimics Microsoft Entra ID login pages. Okta disclosed the campaign on July 10, 2026.

Verified Facts

  • The threat actor O-UNC-066 targets organizations across multiple sectors
  • Attackers use voice calls to direct victims to phishing sites for passkey enrollment
  • The phishing kit is capable of targeting the Entra passkey enrollment process

Evidence

  • The Hacker News article dated July 10, 2026
  • SecurityWeek article dated July 10, 2026

Impact

Organizations using Microsoft 365 should educate users about vishing attacks and verify any unsolicited requests for passkey enrollment. Multi-factor authentication (MFA) policies should be reviewed to prevent unauthorized enrollment.

Confidence Level: High

Sources The Hacker News | SecurityWeek

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings