UNC6692 abused Microsoft Teams interactions to deliver the Snow malware toolkit Attackers tracked as UNC6692 used email bombing followed by Microsoft Teams helpdesk impersonation to pressure targets into installing a fake patch. The payload chain delivered SnowBelt, a malicious browser extension, alongside SnowGlaze, a tunneler, and SnowBasin, a Python backdoor used for command execution and covert communications. The intrusion chain relied on scheduled tasks, startup-folder persistence, a headless Microsoft Edge instance, and WebSocket tunneling to hide activity and maintain access. Threat reporting said the operators used this approach to pursue credential theft, deep network compromise, and domain takeover, which makes the campaign more than a simple phishing incident. The broader implication is that Teams and remote support workflows have become primary attack surfaces, especially when employees are used to interacting with IT staff through chat and remote assistance. Because the operators leaned on legitimate tools and administrative protocols, post-compromise activity can blend into normal support activity and delay detection. Bitwarden confirmed a short-lived supply chain compromise affecting its CLI npm package A malicious @bitwarden/cli version 2026.4.0 was briefly distributed through npm on April 22, 2026, after attackers compromised the package’s delivery path. Bitwarden said the incident affected only the npm distribution mechanism for the CLI during a limited window and that it found no evidence of impact to vault data, production data or production systems. Reporting said the malicious package added a custom loader and credential-stealing logic capable of harvesting secrets from developer environments and potentially spreading into other projects. The incident was linked to a broader developer-tooling supply-chain campaign, which increases the risk because poisoned builds can move from one workstation into CI/CD systems and downstream releases. This matters operationally because password managers, CLIs, and package managers sit close to secrets, automation pipelines, and deployment workflows. A short-lived compromise