AI and IT News Recap: June 30, 2026: A Critical libssh2 Flaw Goes Public, Microsoft Purges 119 Malicious Browser Extensions, and WhatsApp Hands 3 Billion Users a Privacy Shield

By Noah Smith, Owner & Consultant, KeyChange Technologies ยท June 30, 2026

Hand-drawn pen-and-ink editorial illustration of an ornate brass key with a crack splitting through it, symbolizing a critical flaw in the libssh2 SSH library.

A quieter day on the AI front, but a loud one for security. The biggest AI and IT news this Tuesday is a critical SSH library flaw that just went public with working exploit code, a pair of browser-extension purges by Microsoft, a software supply-chain trap aimed straight at developers, and a privacy change coming to three billion phones.

๐Ÿ“Œ The AI and IT news at a glance

  • ๐Ÿ”“ A critical libssh2 flaw (CVE-2026-55200) gets a public exploit that can hit anything using curl, Git, or PHP.
  • ๐Ÿงน Microsoft pulls 119 malicious Edge extensions that hid malware inside images and fonts for years.
  • ๐Ÿ”Ž A fake "Perplexity" Chrome extension logged every search and keystroke before Google removed it.
  • ๐Ÿ“ฆ Hijacked npm and Go packages quietly deploy an infostealer through a VS Code trick.
  • ๐Ÿ’ฌ WhatsApp opens usernames to 3 billion users, letting people hide their phone numbers.

๐Ÿ” Top story: a critical libssh2 flaw goes public, and it is hiding in software you already run

A public proof-of-concept exploit is now circulating for CVE-2026-55200, a critical vulnerability in libssh2, the client-side SSH library quietly embedded in curl, Git, PHP, backup agents, firmware updaters, and a long tail of appliances. The flaw is an integer overflow in the function that parses incoming SSH packets during the handshake. A malicious or compromised SSH server can send a crafted packet that corrupts memory on the connecting client, with possible remote code execution. There are no credentials and no user interaction required, and the bug affects every release up to and including version 1.11.1. It carries a CVSS 4.0 score of 9.2.

The reason this one is worth your attention is distribution. libssh2 is not a product you install and patch in one place. It is statically linked into countless tools and devices, so a routine package update often will not touch the vulnerable copy, and you may not even know it is there. The fix was merged on June 12, but the public PoC released this week changes the urgency: the window between "researchers know" and "attackers have working code" has effectively closed.

In short: A public exploit dropped for a critical libssh2 SSH flaw that can run code on any client connecting to a malicious server.

What it means for your business: Any system that makes outbound SSH-style connections through curl, Git, or embedded firmware could be exposed, so ask your IT provider to inventory where libssh2 lives and confirm patched builds are rolling out.

My take: The scary part here is not the CVSS score, it is the "you may not know it is there" problem. Statically linked libraries are the asbestos of modern software. Worth one direct question to whoever manages your systems: do we have a way to find this, or are we hoping we do not have it?

Source: The Hacker News: Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw


๐Ÿ›ก๏ธ IT and security

Microsoft removes 119 malicious Edge extensions that hid malware in images and fonts

Microsoft shut down a long-running malicious operation on the Edge Add-ons store, tying 119 extensions to a single threat actor active since at least 2021. Dubbed StegoAd, a mash-up of steganography and adware, the extensions hid their payloads inside ordinary image and font files, then woke up days after install to steal credentials and run ad fraud. They were the kind of add-ons people install without a second thought: ad blockers, VPNs, translators, and video downloaders, each one doing its advertised job and collecting good reviews while the malicious code stayed dormant. Combined, the 119 extensions had an install base of up to 2.6 million users, though Microsoft notes evasion checks meant the payload never fired for many of them.

In short: Microsoft pulled 119 Edge extensions from a single actor that smuggled malware inside image and font files and sat dormant for years.

What it means for your business: Browser extensions are software running inside your team's logged-in sessions, so it is worth setting a short approved-extensions policy rather than letting anyone install anything.

My take: "It had good reviews and did its job" is exactly how these survive. The lesson is not to fear extensions, it is to treat them like any other vendor: few, vetted, and reviewed periodically.

Source: The Hacker News: Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts


A fake "Perplexity" Chrome extension logged every search and keystroke

Microsoft's Defender team found a malicious Chrome extension posing as the AI search engine Perplexity. Called "Search for perplexity ai," it used a look-alike domain (perplexity-ai[.]online) to pass for the real service. Once installed, it set itself as the browser's default search engine and routed every query, along with each character typed into the address bar, through an attacker-controlled server before redirecting users to real results. Microsoft found no proof of password theft, but the extension had far more access than a search box should ever need. Google removed it from the store after responsible disclosure.

In short: A counterfeit Perplexity extension intercepted users' searches and address-bar input before Google pulled it.

What it means for your business: Popular AI brand names are now bait, so confirm staff install tools only from official vendor links rather than search results or store look-alikes.

My take: This is the predictable downside of every hot AI brand: impersonators follow the hype. A good habit is to bookmark the real tools your team uses and install only from those bookmarks.

Source: The Hacker News: Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input


๐Ÿค– Tooling and the developer supply chain

Hijacked npm and Go packages deploy a Python infostealer through a VS Code trick

JFrog researchers uncovered two hijacked npm packages, html-to-gutenberg and fetch-page-assets, plus a cluster of Go packages, designed to drop a Python-based information stealer on Windows, Linux, and macOS machines. The clever part is the delivery: instead of the usual npm install-time scripts, the malware hides execution inside a VS Code task configured to run automatically the moment the project folder is opened in the editor. From there it pulls encrypted JavaScript out of blockchain transaction data, opens a backdoor, and deploys an infostealer that hunts for credentials, browser data, crypto wallets, developer tools, and environment secrets.

In short: Hijacked npm and Go packages use an auto-running VS Code task to install an infostealer targeting developer credentials and secrets.

What it means for your business: If your team or contractors write code, a single poisoned dependency can leak the keys to your cloud and customer data, so dependency review and secret scanning are not optional.

My take: Opening a project folder should not be a security event, but here it is. For any business that ships software or relies on contractors who do, this is a reminder that "we vibe-coded it fast" and "we checked what we installed" need to both be true.

Source: The Hacker News: Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer


๐Ÿ’ฌ Privacy and platforms

WhatsApp opens usernames to 3 billion users, letting people hide their phone numbers

WhatsApp announced the global rollout of username reservations, one of its biggest privacy updates to date. The optional feature lets its three billion-plus users connect without sharing a phone number. Reservations start now, with the full feature arriving later this year. By design it is a privacy tool and not a social handle: there is no directory to browse and no search, so someone needs your exact username to reach you, and an optional four-digit key can be required before a stranger can add you. Usernames must be 3 to 35 characters using lowercase letters, numbers, periods, and underscores, and Meta is letting organizations and small businesses claim theirs, including the option to match an existing Facebook or Instagram username.

In short: WhatsApp opened username reservations for 3 billion users, letting them communicate without exposing their phone numbers.

What it means for your business: If you use WhatsApp for customer contact, reserve your business name now before someone else does, the same way you would with a social handle.

My take: The land-grab on business names is the practical action item here. Whatever you think of Meta, claiming your brand's username costs nothing today and avoids a headache later.

Source: BleepingComputer: WhatsApp rolls out usernames to help users hide their phone number


That is the AI and IT news for June 30, 2026. For yesterday's roundup, see our June 29 recap.