This weekly threat intelligence bulletin covers multiple active exploitation campaigns and critical vulnerabilities. Lazarus-linked Operation Dream Job is actively exploiting CVE-2026-68820 (Windows WinSock driver) for privilege escalation and security tool disabling while targeting defense organizations. Apple CVE-2026-65400 (macOS Screen Sharing, CVSS 9.8) is under active exploitation delivering Monero miners. A suspected China-linked campaign deployed autonomous AI agents against Taiwanese government systems, and Kimsuky is building an offline AI environment to automate cyberespionage workflows. Microsoft's August Patch Tuesday addressed 421 vulnerabilities including 42 critical flaws.
CVE-2026-68820
3 posts
17th August – Threat Intelligence Report CISA Adds Three Known Exploited Vulnerabilities to Catalog (CVE-2026-20349, CVE-2026-68820, CVE-2026-72898) CISA added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. The vulnerabilities span Cisco Secure Firewall ASA/FTD (heap inspection), Microsoft Windows AFD WinSock (use-after-free), and Metabase (SQL injection). Federal agencies are required to remediate these on publicly exposed assets under BOD 26-04, and CISA encourages all organizations to prioritize patching.
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack Check Point Research documents a new wave of Operation Dream Job by DPRK-linked Lazarus group targeting the defense sector in Europe and India. The campaign uses two infection chains: DLL sideloading via a legitimate PDF viewer and a trojanized SecurityPDF viewer, both delivering MISTPEN downloader or Troy backdoor. The threat actor exploited CVE-2026-68820, a zero-day in Windows AFD.sys, to deploy FudModule v3.1 kernel rootkit for SYSTEM-level EDR disabling. C2 infrastructure relies on compromised Roundcube and WordPress servers running RelayShell, a novel PHP webshell acting as a communication relay.