EACA Summit 2026 was July 2–3, 2026 — see you next year!
East Africa Cyber & AI Summit
All news
SECURITY BRIEFINGJUNE 29, 20263 min read

Security Briefing | June 29, 2026 - Critical libssh2 PoC Released, Microsoft Pulls 119 Malicious Edge Extensions, KDDI Breach Exposes 14.2M Email Logins

A public proof-of-concept exploit is now available for CVE-2026-55200, a critical libssh2 vulnerability (CVSS 9.2) that allows a malicious SSH server to compromise a connecting client without user interaction. Microsoft removed 119 Edge extensions hiding malware via steganography in images and fonts as part of a campaign active since 2021. Meanwhile, Japanese telecom KDDI disclosed a breach exposing up to 14.2 million email logins across six ISPs.

By EACA Summit Content Team

Security Briefing | June 29, 2026 - Critical libssh2 PoC Released, Microsoft Pulls 119 Malicious Edge Extensions, KDDI Breach Exposes 14.2M Email Logins

1. Public PoC Released for Critical libssh2 CVE-2026-55200

A public proof-of-concept exploit is now available for CVE-2026-55200, a critical vulnerability in libssh2 (CVSS 9.2) that allows a malicious SSH server to trigger memory corruption on a connecting client, potentially leading to code execution without user interaction. The flaw affects all libssh2 versions up to and including 1.11.1.

Verified Facts

  • CVE-2026-55200 affects libssh2 versions up to 1.11.1
  • CVSS 4.0 score of 9.2
  • Public PoC has been released
  • No credentials or user interaction required for exploitation

Evidence

  • CVE-2026-55200
  • CVSS 4.0 score 9.2

Impact

This vulnerability poses a significant risk to any system using libssh2 as an SSH client, as a compromised or malicious server can remotely compromise the client without any user action. Defenders should immediately update libssh2 to the latest patched version and monitor for exploitation attempts.

Confidence Level: High

The Hacker News

2. Microsoft Removes 119 Edge Extensions Hiding Malware via Steganography

A wolf wearing a sheep's wool disguise stalking through a dark server room with neon circuit lines on the floor, representing malicious browser extensions hiding malware inside innocent-looking image and font files.

Microsoft has taken down 119 malicious Edge extensions associated with a campaign dubbed 'StegoAd', active since at least 2021. The extensions used steganography to hide payloads in image and font files, activating days after installation to steal credentials and conduct ad fraud.

Verified Facts

  • 119 malicious Edge extensions removed by Microsoft
  • Campaign named StegoAd by Microsoft
  • Malware used steganography to hide payloads in images and fonts
  • Extensions activated days after installation to steal credentials and run ad fraud

Evidence

  • Microsoft official statement
  • StegoAd campaign designation

Impact

This highlights the ongoing risk of malicious browser extensions that can evade initial detection. Defenders should review installed extensions, enforce allowlisting policies, and educate users about the risks of installing unknown extensions.

Confidence Level: High

The Hacker News

3. Data Breach at KDDI Exposes 14.2 Million Email Logins Across Six ISPs

Japanese telecom KDDI disclosed a data breach where attackers gained access to an email system used by five other ISPs, potentially exposing up to 14.2 million email logins. The breach underscores the cascading risk when a single provider's infrastructure is compromised, affecting multiple downstream services.

Verified Facts

  • KDDI Corporation disclosed a data breach
  • Up to 14.2 million email logins potentially exposed
  • Breach affected KDDI and five other ISPs
  • Attackers accessed an email system

Evidence

  • KDDI official disclosure

Impact

This breach demonstrates the supply chain risk in telecommunications. Affected users should change passwords and enable multi-factor authentication. Organizations relying on these ISPs should monitor for credential stuffing and phishing attacks.

Confidence Level: High

BleepingComputer

All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.

Next step

Continue with the official EACA Summit 2026 program.

View All Briefings