# Threat Intel Brief — August 13, 2026
TL;DR
- Lazarus exploits Windows zero-day (CVE-2026-68820) in Operation Dream Job campaign targeting defense and aerospace firms across France, Germany, Brazil, and India with SYSTEM-level privilege escalation.
- Microsoft patches 398 vulnerabilities including three zero-days; CVE-2026-68820 actively exploited, CVE-2026-62832 and CVE-2026-72971 publicly disclosed.
- Critical Adobe Commerce flaw (CVE-2026-71362) under active exploitation enables unauthenticated account hijacking on e-commerce platforms.
- VMware vCenter CVE-2026-59310 exploited in the wild for remote code execution; attackers deploy persistent backdoors via reverse SSH.
- 737 malicious Chrome VPN extensions route traffic through attacker-controlled SOCKS5 proxies, targeting Russian-speaking users with 75,000+ installs.
---
Critical Threats
Lazarus Exploits Windows Zero-Day in Defense Sector Espionage
What happened:
North Korean state-sponsored group Lazarus exploited CVE-2026-68820, a use-after-free vulnerability in the Windows AFD.sys driver, to achieve SYSTEM-level privilege escalation on Windows 11 and Windows Server 2025 systems. The zero-day was weaponized as part of Operation Dream Job, a multi-year campaign using fraudulent LinkedIn recruitment lures to target defense, aerospace, and aviation organizations. Attackers deployed the FudModule 3.1 rootkit to disable endpoint detection and tamper with Smart App Control, alongside the previously unknown Troy backdoor for reconnaissance and data exfiltration. The campaign also leveraged CVE-2025-49113 to compromise Roundcube webmail servers for command-and-control infrastructure.
Impact:
Confirmed targeting of defense and aerospace entities in France, Germany, Brazil, and India. The zero-day enables attackers with initial access to escalate to full system control, bypassing security products and establishing persistent access to sensitive networks. Compromised organizations face risks of intellectual property theft related to military technologies, surveillance systems, and aerospace engineering. Microsoft patched CVE-2026-68820 in the August 2026 Patch Tuesday release, but the public disclosure and active exploitation create a narrow window for unpatched systems.
Recommendations:
- Deploy Microsoft August 2026 Patch Tuesday updates immediately, prioritizing CVE-2026-68820 on all Windows endpoints and servers.
- Hunt for FudModule rootkit indicators: monitor for unsigned kernel driver loads (Sysmon Event ID 6), Smart App Control registry tampering, and EDR telemetry gaps.
- Review authentication logs on Roundcube webmail servers for CVE-2025-49113 exploitation; scan for RelayShell PHP webshell using published YARA rules.
- Implement security awareness training on Operation Dream Job tactics, emphasizing verification of LinkedIn recruiters and scrutiny of job-related file downloads.
- Monitor for Troy backdoor activity: unusual Microsoft Graph API or OneDrive C2 traffic, in-memory DLL injection, and screen capture operations.
---
Microsoft August Patch Tuesday: 398 Vulnerabilities, Three Zero-Days
What happened:
Microsoft released security updates addressing 398 vulnerabilities across Windows and supported products, including 42 critical-severity flaws. Three zero-day vulnerabilities were disclosed: CVE-2026-68820 (Windows AFD.sys driver, actively exploited by Lazarus), CVE-2026-62832 (Windows User Profile Service privilege escalation, publicly disclosed as "LegacyHive"), and CVE-2026-72971 (Windows Container Isolation tampering, publicly disclosed). The scale of this patch cycle represents one of the largest in recent years, straining IT teams managing deployment across enterprise environments.
Impact:
CVE-2026-68820 enables local attackers to gain SYSTEM privileges via race condition exploitation without user interaction, confirmed in active use by nation-state actors. CVE-2026-62832 allows non-admin users to modify registry hives and execute commands as administrator when an admin logs in. CVE-2026-72971 permits authenticated attackers to tamper with container isolation and gain admin privileges. All three require local access but no user interaction. The volume of patches increases testing burden and creates exploitation windows as organizations stage deployments.
Recommendations:
- Prioritize patching CVE-2026-68820, CVE-2026-62832, and CVE-2026-72971 on systems with local user access or multi-user environments within 72 hours.
- Test cumulative updates (Windows 11 KB5121003/KB5120240, Windows 10 KB5120249) in staging environments for 24-48 hours before production deployment.
- Monitor Windows Security Event Logs (Event ID 4657, 4663, 4672, 4688) for registry hive loads, privilege escalation attempts, and unusual SYSTEM-level process creation.
- Review local user account permissions and disable unnecessary local accounts to reduce attack surface for privilege escalation zero-days.
- Coordinate with application owners to validate business-critical systems post-patch given the 398-flaw scope.
---
Adobe Commerce CVE-2026-71362 Actively Exploited for Account Hijacking
What happened:
Attackers are actively exploiting CVE-2026-71362, a critical vulnerability in Adobe Commerce and Magento e-commerce platforms that allows unauthenticated session hijacking. The flaw enables attackers to switch customer sessions and gain unauthorized access to accounts without credentials, authentication, or user interaction. Sansec Shield WAF is blocking live exploitation attempts, contradicting Adobe's initial assessment that no exploits were known. Adobe released isolated security patches in August 2026 for all supported release lines.
Impact:
Online retailers using Adobe Commerce or Magento face immediate risk of customer account compromise, exposing payment information, order history, and personal data. Successful exploitation enables data breach, fraud, and regulatory compliance violations under PCI-DSS and GDPR. The vulnerability affects customer identity handling mechanisms, allowing attackers to impersonate legitimate users and access private customer portals.
Recommendations:
- Apply Adobe's August 2026 isolated security patches immediately for all Adobe Commerce, Commerce B2B, and Magento installations.
- Verify you are running the latest -p release for your supported branch before applying the isolated patch (patches are not distributed as full releases or Composer packages).
- Enable WAF rules to block CVE-2026-71362 exploitation attempts if using Sansec Shield or similar web application firewalls.
- Monitor authentication logs and customer session activity for anomalous account access patterns, especially session switches without proper authentication.
- Review customer accounts for unauthorized access since vulnerability disclosure; notify affected customers per breach notification requirements if compromise is detected.
---
VMware vCenter CVE-2026-59310 Exploited for Remote Code Execution
What happened:
Threat actors are actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom VMware vCenter Server (CVSS 9.8) that allows remote code execution. QUIRSO observed successful compromises starting August 3, 2026, five days after Broadcom's disclosure. Attackers deploy reverse_ssh for persistent remote access via malicious cron jobs, bypassing inbound security controls. The campaign has compromised 361 unique victim IPs across 47 countries, primarily in Germany, US, Turkey, Iran, and France. Suspected APT actor involvement.
Impact:
vCenter servers manage virtualized infrastructure across enterprise environments, making them high-value targets. Successful exploitation leads to full server control, persistent backdoor access, and potential lateral movement across virtual environments. Attackers can exfiltrate data, disrupt operations, and compromise entire virtual machine estates. Broadcom released patches in late July 2026, but rapid exploitation demonstrates the narrow window between disclosure and weaponization.
Recommendations:
- Immediately apply Broadcom patches for CVE-2026-59310 released in VMSA-2026-0006 to all VMware vCenter Server instances.
- Hunt for indicators of compromise: search for unauthorized cron jobs, reverse_ssh binaries, and unexpected outbound SSH connections on vCenter appliances.
- Review vCenter logs for directory traversal patterns (path traversal activity) between July 28 and present, especially around August 3 timeframe.
- Block or monitor outbound connections from vCenter servers to unknown external IPs; investigate any reverse SSH traffic.
- Audit network access controls to vCenter servers and restrict exposure to trusted management networks only.
---
Threat Actor Activity
Sandworm Targets IT Professionals with Trojanized VPN
Russian-linked threat group Sandworm (APT44, UAC-0145 subgroup) is conducting a social engineering campaign targeting Ukrainian IT workers and system administrators through fake job recruitment since at least May 2026. Attackers impersonate legitimate European IT firms (Sopra Steria Bulgaria) via job sites, Telegram, and Zoom video interviews, delivering trojanized WireGuard VPN clients branded "SopraVPN." The modified client includes a non-standard "SymmetricKey" configuration option that decrypts and executes embedded PowerShell code, establishing persistence via scheduled tasks and downloading secondary payloads. The campaign demonstrates sophisticated OPSEC through domain impersonation (soprasteria-bg[.]com) and multi-platform payload delivery targeting both Windows and Linux systems.
Defensive actions:
- Restrict VPN client installations to approved, cryptographically signed versions distributed through internal channels; block execution of unsigned or third-party VPN clients.
- Monitor for non-standard WireGuard configuration parameters, particularly custom options like 'SymmetricKey', through configuration file inspection.
- Implement EDR solutions with continuous monitoring for scheduled task creation (T1053.005) and unusual PowerShell execution.
- Conduct security awareness training on recruitment-themed social engineering, emphasizing verification of recruiter identities through official company channels.
---
North Korean IT Worker Infiltration Documented
Security researchers conducted an undercover operation creating a fake cryptocurrency startup and hiring three individuals suspected to be North Korean operatives. The investigation documented systematic identity fraud involving AI-generated or AI-edited documents (Google Gemini with SynthID watermarks), geographic inconsistencies (Texas residence with California license and New York bank account), and use of VPN infrastructure (AstrillVPN) consistent with DPRK operations. Operatives employed AI-powered job application tools (AIApply, Final Round AI) and 2FA bypass services (2fa.cn). A July 31, 2026 multi-government joint alert confirms sustained North Korean IT worker placement operations targeting Western technology and cryptocurrency firms to generate revenue for the regime.
Defensive actions:
- Implement continuous identity verification throughout employment lifecycle; require periodic re-verification of identity documents and random video calls.
- Monitor for AI-generated identity documents by checking for SynthID watermarks, analyzing image metadata, and flagging geographic inconsistencies.
- Detect host reconnaissance activity (systeminfo, dxdiag, wmic) within first hours of system access; baseline normal onboarding behavior and flag deviations.
- Block or monitor AstrillVPN infrastructure and alert on remote access tool installations (Chrome Remote Desktop) paired with personal account synchronization.
---
DeadLock Ransomware Leverages Blockchain Infrastructure
DeadLock ransomware-as-a-service operation employs decentralized infrastructure using Polygon blockchain smart contracts for C2 configuration storage, Session network for victim communications, and Wasabi cloud service for data hosting. The operation has compromised approximately 80 organizations, predominantly in Europe, across IT, mining, transportation, manufacturing, hospitality, and consumer goods sectors. Microsoft observed deployment by multiple affiliate groups, including at least one actor previously linked to Lynx and INC ransomware ecosystems. The malware uses XChaCha20 encryption with Curve25519 key protection and is configured to avoid systems in former Soviet Union countries, CIS region, Iran, Syria, Oman, and Yemen.
Defensive actions:
- Monitor for backup deletion activity (vssadmin, wbadmin, bcdedit commands) and implement immutable backup solutions with offline or air-gapped copies.
- Implement network monitoring for unusual blockchain RPC endpoint queries (Polygon eth_call traffic) and connections to decentralized networks like Session.
- Deploy cloud-delivered antivirus with EDR in block mode, enable tamper protection, and configure automated investigation and remediation.
- Enable Controlled Folder Access and implement attack-surface reduction rules to block untrusted executables and lateral movement via PsExec and WMI.
---
Geopolitical Context
North Korean Cyber Espionage Intensifies Against Defense Sector
Lazarus Group's exploitation of CVE-2026-68820 in Operation Dream Job represents a continuation of North Korea's strategic cyber espionage program targeting defense-industrial base entities across multiple continents. The campaign's focus on France, Germany, Brazil, and India reflects intelligence collection priorities aligned with DPRK weapons development programs and efforts to circumvent international sanctions. The deployment of zero-day vulnerabilities, updated rootkit variants (FudModule 3.1), and previously unknown backdoors (Troy) indicates sustained state-level investment in vulnerability research and development capabilities. The abuse of compromised legitimate web infrastructure (Roundcube instances) demonstrates operational maturity and improved OPSEC compared to earlier campaigns.
Russian Operations Target Ukrainian IT Infrastructure
Sandworm's fake recruitment campaign targeting Ukrainian IT workers represents tactical evolution in Russian intelligence operations against Ukraine's critical IT workforce. Rather than exploiting software vulnerabilities, the operation targets the human element by impersonating legitimate European IT firms to compromise system administrators with privileged network access. The campaign aligns with broader Russian strategic objectives to degrade Ukrainian resilience by penetrating IT supply chains and gaining persistent access to enterprise networks. The impersonation of Sopra Steria Bulgaria—a legitimate EU-based consulting firm—may erode trust in cross-border recruitment and remote work practices across Central and Eastern Europe.
---
Recommended Actions
Immediate (0-24 hours)
- Patch CVE-2026-68820, CVE-2026-71362, CVE-2026-59310: Deploy Microsoft August 2026 updates, Adobe Commerce patches, and VMware vCenter VMSA-2026-0006 to all affected systems.
- Hunt for active exploitation: Search for FudModule rootkit indicators, reverse_ssh binaries on vCenter, and anomalous Adobe Commerce session activity.
- Audit Chrome extensions: Remove any of the 737 identified malicious VPN/proxy extensions; verify proxy settings are set to 'Direct' or corporate-approved values.
- Block malicious infrastructure: Implement network blocks for known Sandworm domains (soprasteria-bg[.]com), Lazarus C2 infrastructure, and SOCKS5 proxies on port 1082.
Short-term (24-72 hours)
- Patch remaining August 2026 vulnerabilities: Apply updates for CVE-2026-62832, CVE-2026-72971, CVE-2026-20349 (Cisco ASA/FTD), CVE-2026-55040 (SharePoint), CVE-2026-58231 (SAP Commerce Cloud), and CVE-2026-48362 (Adobe ColdFusion).
- Rotate credentials: If LiteLLM 1.82.7/1.82.8 was installed March 24, 2026, rotate all cloud keys, SSH keys, Kubernetes tokens, database passwords, and API keys accessible in affected Python environments.
- Review recruitment processes: Implement enhanced identity verification for IT hiring, including document forensics, geographic consistency checks, and periodic re-verification post-hire.
- Deploy EDR monitoring: Configure detection for scheduled task creation, PowerShell execution via VPN clients, and blockchain RPC endpoint queries.
This week
- Test and deploy remaining patches: Complete testing and production rollout of Microsoft, Adobe, Cisco, SAP, and VMware security updates across enterprise environments.
- Audit cloud portal configurations: Review Salesforce Experience Cloud and ServiceNow customer portal sharing rules, permissions, and guest user access controls.
- Implement MFA enforcement: Deploy multi-factor authentication across all social media, cloud services, and online accounts to mitigate credential theft campaigns.
- Conduct security awareness training: Educate users on Operation Dream Job tactics, fake recruitment lures, malicious VPN extensions, and sextortion phishing campaigns.
---
Watch List
- ShieldBreak bypass of CVE-2026-50656: Monitor for Microsoft emergency patch addressing the publicly released PoC that bypasses the July 2026 RoguePlanet fix.
- SharePoint CVE-2026-55040 exploitation: Track for increased exploitation following Rapid7's August 11 PoC release; Defused reported weaponized attacks within 24 hours.
- Kimwolf v7 botnet expansion: Monitor for HTTP/2 DDoS traffic from Android TV boxes and IoT devices using Ethereum ENS for C2 resolution.
- City-Forum campaign evolution: Watch for expansion beyond Salesforce and ServiceNow to other cloud portal platforms; infrastructure (158.220.87.79, city-forum.com) remains active since March 2025.
- WindRelay + SpyNote Android campaign: Track for geographic expansion beyond Czechia, Slovakia, and Slovenia; campaign active through July 2026 with live loan fraud and NFC relay attacks.
---
Sources
- BleepingComputer: Lazarus hackers exploited Windows zero-day to target defense firms; Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days; Hackers exploit critical Adobe Commerce flaw to hijack customer accounts; Cisco warns of ASA and FTD VPN flaw exploited to crash devices; DeadLock ransomware uses blockchain to resist infrastructure takedown; Sandworm hackers target IT pros with trojanized WireGuard VPN client; Hundreds of fake Chrome VPN extensions route traffic through a proxy; Hackers leverage new Microsoft SharePoint exploit in attacks; Android malware combo takes out loans and relays victims' credit cards; Plug and Pwn attack uses fake USB devices for Windows SYSTEM access; FBI warns of hackers targeting online accounts to steal explicit photos; Wesco confirms security incident after ExfilSquad claims data theft; "City-Forum" data-theft attacks target Salesforce, ServiceNow portals
- The Hacker News: Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor; Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack; Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws; Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access; 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies; Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations; SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code; ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access; Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS; Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands; Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE; DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt; Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing; Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client; A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices; Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo; Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers; OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
- Krebs on Security: Microsoft Plugs Nearly 400 Security Holes
- Unit 42 (Palo Alto Networks): Kimwolf v7: An Evolution of the Kimwolf Botnet
- CERT.BE (Belgium): Warning: Microsoft Patch Tuesday August 2026 patches 398 vulnerabilities
