This weekly threat intelligence bulletin covers multiple active exploitation campaigns and critical vulnerabilities. Lazarus-linked Operation Dream Job is actively exploiting CVE-2026-68820 (Windows WinSock driver) for privilege escalation and security tool disabling while targeting defense organizations. Apple CVE-2026-65400 (macOS Screen Sharing, CVSS 9.8) is under active exploitation delivering Monero miners. A suspected China-linked campaign deployed autonomous AI agents against Taiwanese government systems, and Kimsuky is building an offline AI environment to automate cyberespionage workflows. Microsoft's August Patch Tuesday addressed 421 vulnerabilities including 42 critical flaws.
Operation Dream Job
2 posts
17th August – Threat Intelligence Report Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack Check Point Research documents a new wave of Operation Dream Job by DPRK-linked Lazarus group targeting the defense sector in Europe and India. The campaign uses two infection chains: DLL sideloading via a legitimate PDF viewer and a trojanized SecurityPDF viewer, both delivering MISTPEN downloader or Troy backdoor. The threat actor exploited CVE-2026-68820, a zero-day in Windows AFD.sys, to deploy FudModule v3.1 kernel rootkit for SYSTEM-level EDR disabling. C2 infrastructure relies on compromised Roundcube and WordPress servers running RelayShell, a novel PHP webshell acting as a communication relay.