TL;DR
Microsoft issued its largest patch batch ever (974 holes) with four new CVEs disclosed; fake LastPass installers distribute a Microsoft-signed kernel driver that disables antivirus before deploying password stealers; Google hit with €numerous GDPR fine for location data mishandling.
Executive Summary
- Microsoft released patches for 974 security holes, marking the company’s largest single patch batch; four new CVEs were explicitly identified in this release.
- Attackers are distributing counterfeit LastPass Authenticator installers via GitHub that deploy a Microsoft-signed kernel driver to disable security products before running password stealers.
- Google was fined €403 million by Ireland’s Data Protection Commission for GDPR violations in how it processed location data from May 2018 to February 2020.
- Researchers disclosed a new TASK#STOMP PowerShell backdoor campaign designed to exfiltrate business documents, WiFi passwords, and clipboard data.
- ShinyHunters cybercriminals took control of the Clop ransomware group’s dark web leak site and demanded extortion payment.
Top Threats Today
1. Microsoft’s Record Patch Batch Signals Accelerated Vulnerability Discovery
Severity: HIGH Affected: Technology
Microsoft issued updates to plug at least 974 security holes in Windows operating systems and other software, representing by far its largest single patch batch ever [1]. Four CVEs were named in the release: CVE-2026-69730, CVE-2026-69829, CVE-2026-81963, and CVE-2026-85880 ⚠[1]. Security experts have warned that while Microsoft attributes the acceleration to AI-assisted vulnerability discovery, many of the newly patched flaws may face rapid exploitation [1].
Sources:[1] Krebs on Security
Recommended Action
- Prioritize patching for critical and high-CVSS holes across Windows and Microsoft software within 30 days.
- Monitor security vendor advisories for active exploitation reports linked to these four newly disclosed CVEs.
- Test patches in a staging environment before enterprise deployment to avoid stability issues.
2. Fake LastPass Installers Deploy Microsoft-Signed Kernel EDR Killer
Severity: HIGH Affected: Technology
Attackers are distributing fake LastPass Authenticator installers on GitHub that install a Windows kernel driver to disable antivirus and EDR (endpoint detection and response) software before a password stealer named “Rapuncel” executes [1][2]. Researchers at LastPass and Delphos Labs reported the campaign, which impersonates at least 40 companies and disables 145 security products [2]. The malicious driver exploits a Microsoft-signed legitimate component, allowing it to operate with elevated privileges ⚠[1].
Sources:[1] The Hacker News[2] SecurityWeek
Recommended Action
- Alert users not to download LastPass Authenticator from GitHub; direct them to official distribution channels (LastPass website or official app stores).
- Hunt for the presence of unsigned or suspicious kernel drivers in running systems; audit driver load logs.
- Verify EDR/antivirus integrity and confirm service status on high-risk endpoints; implement application whitelisting for driver installation.
3. Google Fined €403 Million for GDPR Location Data Violations
Severity: MEDIUM Affected: Technology
Ireland’s Data Protection Commission fined Google €403 million ($463 million) for GDPR violations related to the company’s handling of users’ location data between May 2018 and February 2020 [1][2][3]. The regulator also ordered Google to cease certain processing practices [1]. This penalty underscores regulatory pressure on large technology vendors to implement transparent consent mechanisms and data minimization practices [4].
Sources:[1] The Hacker News[2] BleepingComputer[3] The Record[4] SecurityWeek
Recommended Action
- Review your organization’s use of third-party location data services and verify that data processing agreements include explicit GDPR compliance clauses.
- Audit location data retention policies and ensure users receive clear, granular consent requests.
- Monitor regulatory updates from EU data protection authorities for similar fines or enforcement trends.
4. TASK#STOMP PowerShell Backdoor Harvests Sensitive Data
Severity: HIGH Affected: Technology
Cybersecurity researchers disclosed a new campaign dubbed TASK#STOMP that deploys a PowerShell backdoor designed to automatically harvest and exfiltrate business documents, monitor the filesystem for new files in real-time, and steal WiFi passwords and clipboard data from compromised hosts [1]. The backdoor’s automated document harvesting capability and broad data exfiltration scope suggest targeting of organizations with sensitive intellectual property or financial records [1].
Sources:[1] The Hacker News
Recommended Action
- Hunt for PowerShell execution logs showing suspicious script loading or file transfer activity; review encoded command history.
- Implement application whitelisting to restrict unsigned PowerShell scripts and script block logging across the enterprise.
- Segment sensitive document stores and apply network-level egress controls to limit data exfiltration.
5. ShinyHunters Hijacks Clop Ransomware Leak Site
Severity: MEDIUM Affected: Technology
The ShinyHunters extortion group has taken control of the Cl0p ransomware gang’s dark web leak site and claims to have stolen victim data, potentially exposing organizations that previously paid ransoms to renewed extortion threats [1][2]. The defacement signals potential access to Clop’s infrastructure and victim database, creating secondary extortion risk [2].
Sources:[1] Dark Reading[2] The Record
Recommended Action
- If your organization paid a Clop ransom, assume victim data may now be circulating outside Clop’s control and prepare for possible secondary extortion demands.
- Monitor dark web forums and threat feeds for references to your organization in connection with Clop victim lists.
- Review and strengthen incident response plans for ransomware recovery; consider threat intelligence partnerships to monitor Clop and ShinyHunters activity.
Today’s Action Checklist
- ☐ URGENT: Notify endpoint administrators to block GitHub as a source for third-party security tool downloads; verify LastPass Authenticator installation sources across the organization.
- ☐ HIGH PRIORITY: Test and deploy Microsoft’s September patch batch in staging; prioritize CVE-2026-69730, CVE-2026-69829, CVE-2026-81963, and CVE-2026-85880 for review.
- ☐ HIGH PRIORITY: Hunt for TASK#STOMP PowerShell backdoor indicators; review recent PowerShell script executions and clipboard-access attempts on sensitive systems.
- ☐ STANDARD: Verify GDPR data processing agreements with all third-party location-tracking vendors and confirm consent compliance.
- ☐ STANDARD: Check threat intelligence feeds for confirmed victims of Clop ransomware and prepare contingency communications in case secondary extortion attempts occur.