Security Briefing | July 10, 2026 - Unpatched XQUIC DoS Flaw, GigaWiper Combines Wiper and Ransomware, Vishing Campaign Targets Microsoft 365 Passkey Enrollment
An unpatched denial-of-service vulnerability in Alibaba's XQUIC library (XRING) allows any remote client to crash HTTP/3 servers with just 260 bytes of legitimate traffic. Microsoft analyzed GigaWiper, a destructive Windows backdoor combining disk wiping, multi-pass wiping, and fake ransomware into one platform. Okta warns of vishing attacks by threat actor O-UNC-066 tricking Microsoft 365 users into enrolling fake Entra passkeys.
By EACA Summit Content Team

1. Unpatched XRING Flaw in XQUIC Enables Remote Server Crashes
A vulnerability in Alibaba's XQUIC library, dubbed XRING, allows any remote client to crash HTTP/3 servers by sending approximately 260 bytes of legitimate QPACK traffic. The flaw, disclosed by FoxIO researcher Sébastien Féry on July 8, 2026, requires no authentication or malformed packets. No patch is currently available.
Verified Facts
- The XRING flaw exists in XQUIC, Alibaba's QUIC and HTTP/3 library
- A remote client can crash the server with a short burst of legal traffic
- The vulnerability was disclosed on July 8, 2026, by FoxIO researcher Sébastien Féry
- No patch has been released as of July 10, 2026
Evidence
- The Hacker News article dated July 10, 2026
- SecurityWeek article referencing the same disclosure
Impact
Organizations using XQUIC-based HTTP/3 services are at risk of denial-of-service attacks. Defenders should monitor for patches and consider temporary mitigations such as rate limiting or disabling HTTP/3.
Confidence Level: High
Sources The Hacker News | SecurityWeek
2. GigaWiper Backdoor Combines Wiping, Ransomware, and Spyware Capabilities

Microsoft analyzed a destructive Windows backdoor called GigaWiper, which bundles three older malware families into a single platform. The backdoor offers operators commands to wipe disks, overwrite the Windows drive, or execute fake ransomware that scrambles files without a recoverable key.
Verified Facts
- GigaWiper is a Windows backdoor that combines multiple destructive tools
- It includes a standalone wiper, a multi-pass wiping command, and fake ransomware encryption
- Microsoft published a detailed analysis on July 9, 2026
Evidence
- Microsoft Security Blog post dated July 9, 2026
- SecurityWeek article dated July 10, 2026
Impact
This backdoor poses a significant threat to Windows systems, as it can cause irreversible data loss. Defenders should ensure endpoint detection and response (EDR) systems are updated to detect GigaWiper components.
Confidence Level: High
Sources Microsoft Security Blog | SecurityWeek
3. Okta Warns of Vishing Attacks Targeting Microsoft 365 Passkey Enrollment
A threat actor tracked as O-UNC-066 is using voice-based phishing (vishing) to trick Microsoft 365 users into enrolling a fake Entra passkey. The attack leverages a panel-controlled phishing kit that mimics Microsoft Entra ID login pages. Okta disclosed the campaign on July 10, 2026.
Verified Facts
- The threat actor O-UNC-066 targets organizations across multiple sectors
- Attackers use voice calls to direct victims to phishing sites for passkey enrollment
- The phishing kit is capable of targeting the Entra passkey enrollment process
Evidence
- The Hacker News article dated July 10, 2026
- SecurityWeek article dated July 10, 2026
Impact
Organizations using Microsoft 365 should educate users about vishing attacks and verify any unsolicited requests for passkey enrollment. Multi-factor authentication (MFA) policies should be reviewed to prevent unauthorized enrollment.
Confidence Level: High
Sources The Hacker News | SecurityWeek
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



