Last Updated On

Fake Job Offers Unleashed North Korean Rootkit on Aerospace Giants This Week
A North Korean espionage wave used fake job offers to drop a kernel rootkit on defense and aerospace targets while three separate maximum severity flaws hit the known exploited catalog in the same window.
Metabase password reset endpoints turned into unauthenticated admin backdoors Cisco VPN concentrators faced crash on demand attacks and VMware vCenter instances across 47 countries showed active reverse shell persistence.
Supply chain leftovers from March still demand secret rotation and Microsoft Patch Tuesday added hundreds more remote code execution candidates that now require immediate prioritization.
10
CVSS Score
48
IOC Count
18
Source Count
84
Confidence Score
CVE-2026-68820, CVE-2026-20349, CVE-2026-72898, CVE-2026-72899, CVE-2026-72900, CVE-2026-59310, CVE-2026-59309, CVE-2026-58231, CVE-2026-44772, CVE-2026-34265, CVE-2026-44758, CVE-2026-62878, CVE-2026-62893, CVE-2026-62815, CVE-2026-59124, CVE-2026-62832, CVE-2026-72971, CVE-2026-63520, CVE-2026-55040, CVE-2026-33634, CVE-2025-49113, CVE-2026-53413, CVE-2026-53414, CVE-2026-53415
Lazarus Group, TeamPCP, Under Attribution
Defense, Aerospace, Aviation, Manufacturing, Government, Financial Services, Logistics, Technology, E commerce, Business Intelligence, Critical Network Infrastructure
Europe, India, South America, North America, Turkey, Iran, Global
Chapter 01 - Executive Overview
Today's brief is dominated by confirmed in the wild exploitation across edge analytics and endpoint layers anchored by government catalog additions of three known exploited vulnerabilities on 11 August and vendor patching of an actively exploited Windows kernel zero day used in a North Korea linked espionage campaign against defense industry targets. Concurrent reporting covers active VMware vCenter compromise campaigns a maximum severity SAP Commerce Cloud remote code execution flaw with exploitation not confirmed and new scale data on the earlier TeamPCP LiteLLM supply chain compromise.
Lazarus Dream Job Zero Day Critical Defense and Aerospace Threat overview: Consulted sources attribute a new wave of Operation Dream Job to the DPRK linked Lazarus group. Operators lure defense and aerospace staff with fraudulent job offers deliver trojanized PDF tooling escalate via a Windows AFD.sys zero day CVE-2026-68820 to deploy the FudModule kernel rootkit and establish long term access with ForestTiger and a new Troy backdoor. Strategic risk context: Targets include organizations building surveillance sensors drones and robotics with confirmed or observed activity linked to France Germany India and Brazil. A compromised French organization was later abused to spear phish others. Reputation abuse multiplies trust failure beyond the first victim. Severity and business impact: SYSTEM level rootkit plus EDR blinding implies full host compromise potential IP theft and regulatory exposure under export control and national security regimes. Patch is available as of 11 August 2026. Government catalog due date reported as 25 August 2026 for federal entities. Confidence: High on exploitation and technical chain. Medium on full victimology completeness. Leader decision now: Mandate emergency Windows cumulative update deployment for all defense adjacent and executive endpoints within 24 to 48 hours and authorize HR and recruiting security controls against unsolicited job offer file workflows.
Metabase SQL Injection Known Exploited Vulnerability Critical Analytics and Data Platforms Threat overview: CVE-2026-72898 is an unauthenticated SQL injection via Metabase password reset API path. Related flaws CVE-2026-72899 and CVE-2026-72900 expand the surface. Government catalog addition occurred on 11 August 2026. Successful exploitation yields administrator access and theft of stored database credentials. Exploitation against the vendor cloud environment occurred before public disclosure. Strategic risk context: Metabase commonly sits on production data warehouses. Credential theft equals bulk data exposure and lateral movement into databases. Severity and business impact: CVSS 10.0. Confidentiality integrity and availability all high. Regulatory notification risk if personal data is reachable through connected databases. Confidence: High on vulnerability and catalog status. Actor identity unknown. Leader decision now: Inventory all internet reachable Metabase instances tonight. If any remain unpatched take them offline until upgraded to fixed builds.
Cisco ASA and FTD VPN Denial of Service Known Exploited Vulnerability High Network Edge and Remote Access Threat overview: CVE-2026-20349 allows unauthenticated remote denial of service against Cisco Secure Firewall ASA and FTD Remote Access SSL VPN by crafted HTTP requests forcing device reload. Vendor and government catalog confirm active exploitation. Federal remediation due 14 August 2026. Strategic risk context: Edge VPN failure is an availability crisis for remote workforce and partner access. Repeated reload loops equal business stoppage. Severity and business impact: CVSS 8.6. No confidentiality or integrity impact claimed but operational outage risk is immediate. No workarounds per vendor. Confidence: High. Leader decision now: Confirm ASA and FTD version inventory and schedule emergency maintenance windows before the 14 August federal due date. Treat as organization wide SLA regardless of sector.
VMware vCenter Path Traversal Exploitation Critical Virtualization and Cloud Operations Threat overview: Consulted sources document active exploitation of CVE-2026-59310 CVSS 9.8 directory traversal leading to arbitrary code execution with reverse ssh persistence. 361 unique victim IPs across 47 countries. First C2 contact 3 August five days after vendor disclosure. Related scanning for CVE-2026-59309 noted separately. Strategic risk context: vCenter compromise is environment level. ESXi fleets snapshots and identity stores sit behind it. Severity and business impact: Confirmed compromise not mere scanning. Actor under attribution. Confidence: Medium High on exploitation facts. Medium on global scale figures pending broader corroboration. Leader decision now: Verify late July patches on all vCenter instances and authorize incident response hunt for reverse ssh and unexpected cron persistence immediately.
SAP Commerce Cloud Remote Code Execution Critical Retail and E commerce Threat overview: CVE-2026-58231 CVSS 10.0 unauthenticated abuse of a default authentication client in Commerce Cloud Data Hub Adapter enabling arbitrary code execution. Patches released on vendor August patch day. No source in this window confirmed in the wild exploitation. Related critical notes include CVE-2026-44772 CVE-2026-34265 and CVE-2026-44758. Strategic risk context: Customer PII payment adjacent workflows and brand trust. Severity and business impact: Maximum CVSS. Temporary IP filter workaround available. Confidence: High on vulnerability existence. Exploitation status no known exploitation in consulted sources. Leader decision now: Prioritize note application for Commerce Cloud this week. Do not wait for catalog listing.
LiteLLM TeamPCP Supply Chain Impact Dataset High Software Engineering and AI Gateways Threat overview: Consulted sources map loot from the March 2026 LiteLLM malicious PyPI releases 1.82.7 and 1.82.8 themselves downstream of the Trivy TeamPCP UNC6780 supply chain attack CVE-2026-33634 already in catalog since March. Dataset claims reconstructed exposure for 2500 plus organizations and approximately 434000 captured files not proven per organization compromise. Strategic risk context: Long lived cloud keys SSH keys Kubernetes tokens and AI provider API keys remain usable until rotated. Prior guidance warned of delayed weaponization of stolen credentials. Severity and business impact: Potential account takeover and secondary ransomware. Figures require independent verification. Confidence: Medium on scale metrics. High that the March packages were malicious and that credential rotation remains the correct action. Leader decision now: If any CI runner or developer host could have pulled LiteLLM 1.82.7 or 1.82.8 on 24 March 2026 force rotate all secrets those environments could reach. Do not wait for breach confirmation.
Microsoft August 2026 Patch Tuesday Collateral Critical Remote Code Executions Volume reaches approximately 398 to 421 CVEs depending on counter. Approximately 42 to 62 Critical depending on methodology. Three zero days include the exploited CVE-2026-68820 the public elevation of privilege CVE-2026-62832 and the public tampering CVE-2026-72971. Unauthenticated remote code execution priorities not flagged exploited at ship include CVE-2026-62878 DNS Server CVE-2026-62893 WDS TFTP CVE-2026-62815 Microsoft QUIC and CVE-2026-59124 HPC Pack. SharePoint chain completion involves July CVE-2026-55040 authentication bypass plus August CVE-2026-63520 remote code execution half. Prioritize DNS critical remote code executions and DHCP critical. Treat the exploited local privilege escalation as important but not the sole speed driver versus exposed server roles.
Today's Intelligence Quality Source coverage is strong on the Lazarus Microsoft and government catalog cluster. VMware details rest primarily on one incident response firm via secondary amplification. LiteLLM scale claims are single firm dataset analysis with explicit uncertainty. MITRE technique IDs were not published by sources so ATT and CK fields intentionally sparse. Overall brief confidence 84.
Chapter 02 - Threat & Exposure Analysis
Today's landscape is a convergence of nation state zero day post exploitation unauthenticated edge and analytics remote code executions entering the known exploited catalog and delayed blast radius reporting from an AI tooling supply chain event.
CVE-2026-68820 Lazarus Operation Dream Job Zero Day Privilege Escalation Attack progression: Social engineering via fraudulent defense and aerospace job offers. Delivery of encrypted ZIP containing either signed PDF viewer plus malicious libmupdf.dll sideload plus encrypted PDF named payload or trojanized SecurityPDF viewer plus crafted PDF with specific marker string XOR key 0x39 dropping to TEMP new.exe. Chain one loads MISTPEN in memory downloader using Microsoft Graph API and OneDrive C2 with AES encrypted file exchange. Recon modules profile host processes and screenshots. Persistence module installs on disk autorun for MISTPEN. LPE loader negotiates keys four public keys from C2 using Kyber ML KEM post quantum KEM plus GOST CBC session layer and fetches FudModule exploit for CVE-2026-68820 in afd.sys. FudModule v3.1 obtains SYSTEM tears down telemetry callbacks minifilters NT Kernel Logger 94 ETW providers tampers Smart App Control injects elevated MISTPEN. Final backdoors ForestTiger and or new Troy with 17 C2 commands. C2 via compromised Roundcube CVE-2025-49113 plus leaked credentials and PrestaShop hosts running RelayShell PHP relay webshell with at least 17 relay IDs observed. Exploitability: CVSS 7.0 local authenticated code execution prerequisite race condition no user interaction for the LPE step itself. Patched 11 August 2026. Campaign indicators: Job lure PDFs MuPDF based trojanized viewers OneDrive Graph API C2 post quantum key exchange before LPE payload Enveil impersonating sites. Enveil not compromised. Threat actor: Lazarus Group DPRK linked Operation Dream Job. Infrastructure fingerprinting: Compromised Roundcube WordPress PrestaShop ExpressVPN for operator access to RelayShell Trojan C2 IPs and domain. Sector exposure: Defense aerospace aviation military tech sensors drones robotics. Geographic exposure: Western Europe France Germany India Brazil South America global secondary phishing from compromised French organization.
CVE-2026-72898 CVE-2026-72899 CVE-2026-72900 Unauthenticated Metabase SQL Injection to Admin and Database Credential Theft Attack progression: Remote unauthenticated HTTP or HTTPS access to reset password database endpoint or public cards and dashboards exposing field filter dimension parameters. Arbitrary SQL injection into Metabase application database via HoneySQL directive structures merged unparameterized. Yields administrator access then steal stored credentials for connected databases then read or export data. CVE-2026-72900 allows low privileged authenticated user to read entire application database. Exploitability: CVSS 10.0 for primary flaws. No authentication. Requires network reachability to Metabase HTTP or HTTPS. Affected versions: Broad on premises matrix from x.58.0 through x.63.4 series. Fixed builds x.58.24 and later corresponding trains. Actor: Under Attribution. Sector and geographic exposure: Insufficient data for named victim sectors or regions beyond general business intelligence tool deployment. Exploitation confirmed against vendor cloud environment before disclosure with public proof of concept circulating by 10 August 2026.
CVE-2026-20349 Cisco ASA and FTD Remote Access SSL VPN Unauthenticated Denial of Service Attack progression: Crafted HTTP request to Remote Access SSL VPN service insufficient error checking or heap inspection leading to device reload and denial of service. Exploitability: CVSS 8.6 network low complexity no privileges no user interaction high availability impact only. Vulnerable configurations include IKEv2 RA VPN with client services SSL VPN webvpn enable Zero Trust Network Access enabled. No workarounds. Vendor aware of exploitation earlier in August. Actor: Under Attribution. No public detail on targets or success rate beyond exploitation confirmation. Government catalog due date: 14 August 2026 for federal civilian executive branch unusually short reflecting edge criticality.
CVE-2026-59310 VMware vCenter Directory Traversal to reverse ssh Persistence Attack progression: Network accessible path traversal consistent with CVE-2026-59310 leading to code execution then malicious cron deploying reverse ssh for outbound C2 and persistence. First victim to attacker domain contact 3 August 2026 five days post disclosure. Separate scanning and fingerprinting for related CVE-2026-59309 vmdir authentication bypass noted with insufficient evidence to correlate. Exploitability: CVSS 9.8 network access required. Scale: 361 unique victim IPs 47 countries concentration Germany United States Turkey Iran France. Actor: Under Attribution suspected APT.
CVE-2026-58231 SAP Commerce Cloud Data Hub Adapter Unauthenticated Remote Code Execution Attack progression: Abuse default authentication client plus crafted input to insufficiently validated functions leading to arbitrary code execution or internal component compromise. Related critical notes CVE-2026-44772 MII code injection CVE-2026-34265 NetWeaver ABAP DIAG out of bounds write CVE-2026-44758 MII SSTI SSRF to command execution. Exploitability: CVSS 10.0 unauthenticated. Exploitation: Not confirmed in consulted sources for in the wild use. Actor: Under Attribution.
TeamPCP Trivy LiteLLM Delayed Credential Exposure Reporting Attack progression: TeamPCP also known as UNC6780 compromised Aqua Trivy CVE-2026-33634 catalog entry since March incomplete credential rotation retained access malicious trivy action tags plus Trivy 0.69.4 LiteLLM CI consumed poisoned Trivy malicious PyPI 1.82.7 and 1.82.8 approximately 40 minutes from 10:39 UTC 24 March treat installs to 16:00 UTC as suspect litellm_init.pth executes on every Python start steals environment variables SSH keys cloud Kubernetes database AI keys exfils to attacker domain. Campaign indicators: GitHub repositories with tpcp docs prefix release assets data timestamp pattern. Actor: TeamPCP also known as UNC6780. Did not target LiteLLM directly transitive CI compromise. Uncertainty: 2500 organization and 434000 file figures equal reconstructed exposure from loot not confirmed breaches. Named organizations require independent validation.
Microsoft August 2026 Patch Tuesday Collateral Critical Remote Code Executions Volume approximately 398 to 421 CVEs. Approximately 42 to 62 Critical. Three zero days CVE-2026-68820 exploited CVE-2026-62832 public elevation of privilege User Profile Service CVE-2026-72971 public tampering unionfs.sys exploitation unlikely. Unauthenticated remote code execution priorities not flagged exploited at ship CVE-2026-62878 DNS Server CVE-2026-62893 WDS TFTP CVE-2026-62815 Microsoft QUIC CVE-2026-59124 HPC Pack. SharePoint chain completion July CVE-2026-55040 authentication bypass plus August CVE-2026-63520 remote code execution half. Prioritize DNS critical remote code executions and DHCP critical.
Cross Incident Pattern Analysis Edge and management plane appliances remain first hour priorities. Cisco VPN denial of service catalog entry due 14 August and vCenter remote code execution exploitation show attackers still prefer high leverage infrastructure over endpoints alone. Defense sector espionage paired with kernel EDR evasion. Lazarus FudModule v3.1 continues afd.sys zero day tradition. Supply chain credential half life exceeds package half life. Forty minute PyPI window still drives August credential rotation urgency. Unauthenticated data platform SQL injection mirrors unauthenticated commerce remote code execution. Internet facing business apps with default or weak authentication surfaces dominate CVSS 10.0 disclosures this window.
Chapter 03 - Operational Response
Operational posture for the next 24 hours treat known exploited catalog items and confirmed exploitation as emergency change treat CVSS 10.0 unauthenticated remote code executions as near emergency even without catalog entry treat supply chain credential exposure as forced rotation program.
Lazarus CVE-2026-68820 Immediate Response and Containment Containment priorities: Deploy August 2026 Windows cumulative updates enterprise wide prioritizing executive defense program engineering and VDI endpoints. Verify afd.sys file version post patch. Isolate hosts with hits on hash set SecurityPDF binaries or Graph API OneDrive C2 patterns to MISTPEN like behavior. Disable execution of unsigned or sideloaded DLLs beside PDF viewers via application control where feasible. Security hardening actions: Block outbound to IOC domains and IPs at egress. Restrict Microsoft Graph and OneDrive access from non managed or unusual process trees. Force password and session reset for users who opened unsolicited recruiting archives. Hunt RelayShell on any internet facing Roundcube WordPress or PrestaShop the organization operates. Internal security coordination: Notify CISO SOC incident response endpoint engineering HR talent acquisition security Legal for export controlled data risk. Escalation triggers FudModule ForestTiger Troy hash hit SYSTEM level unknown msiexec child chains Smart App Control policy tampering. External if defense contractor follow contractual cyber incident notification clauses consider national CERTs for confirmed Lazarus TTPs. Do this within 24 hours: Full EDR sweep for DLL sideload of libmupdf.dll TEMP new.exe and ETW provider teardown artifacts brief recruiting teams on Dream Job lures.
Metabase CVE-2026-72898 and Related Immediate Response and Containment Containment priorities: Identify all Metabase instances internet facing first. If version in affected ranges either patch immediately or remove from network exposure. After patch invalidate all sessions reset admin passwords rotate every database credential stored in Metabase. Review database audit logs for anomalous queries or new admin users around exploitation window. Security hardening actions: Place Metabase behind SSO MFA and IP allowlists never expose reset endpoints to the open internet. Upgrade to fixed trains. Internal security coordination: Notify SOC Data Platform DBA Privacy officer if personal data databases connected. Escalation evidence of admin creation or bulk extract full incident response plus regulatory assessment. Do this within 24 hours: Credential rotation complete for all connected data sources confirm no residual webshells or cron on Metabase hosts.
Cisco ASA and FTD CVE-2026-20349 Immediate Response and Containment Containment priorities: Inventory ASA and FTD versions and RA VPN webvpn zero trust enablement. Schedule emergency upgrade to fixed trains. Due date pressure 14 August 2026 for federal use as universal internal deadline. Monitor for unexpected reload loops or SSL VPN service crashes treat as possible exploitation attempts. Prepare capacity failover secondary VPN or ZTNA before maintenance. Security hardening actions: No vendor workaround patch only path. Ensure out of band management remains available if VPN plane fails. Rate limit and monitor anomalous HTTP to VPN portals detection aid only not mitigation. Internal security coordination: Notify Network Engineering NOC SOC Business Continuity. Escalation repeated unplanned reloads on internet facing VPN concentrators. Do this within 24 hours: At least complete change plan approval and begin phased upgrades on internet facing pairs.
VMware vCenter CVE-2026-59310 Immediate Response and Containment Containment priorities: Confirm late July patches applied. If unpatched and internet exposed isolate management interfaces immediately. Hunt for reverse ssh binaries unexpected cron entries anomalous outbound SSH from vCenter. Snapshot investigation do not power off without memory capture if compromise suspected follow incident response playbook. Security hardening actions: vCenter management on isolated network only no direct internet. Enforce MFA on vSphere admin rotate vCenter SSO or AD bind credentials if compromise suspected. Track scanning for CVE-2026-59309 but do not conflate campaigns without evidence. Internal security coordination: Notify Virtualization platform owners Cloud or data center operations incident response CISO for confirmed compromise. Escalation reverse ssh on vCenter major incident. Do this within 24 hours: Fleet wide patch verification report to CISO incident response triage on any anomaly.
SAP Commerce CVE-2026-58231 Immediate Response and Containment Containment priorities: Apply August Commerce Cloud fixed release and redeploy. Until patched IP filter set restricting access to vulnerable Data Hub Adapter endpoint. Review application and server logs for unauthenticated abuse of default authentication client. Security hardening actions: Patch related criticals. Post related patch maintain Secure Transformer allowed hosts for XSL. Internal security coordination: Notify E commerce platform owners SAP BASIS AppSec Fraud or Customer support if downtime. Do this within 24 hours: Confirm patch deployment status in non production then production pipeline.
LiteLLM TeamPCP Credentials Immediate Response and Containment Containment priorities: Search package inventories lockfiles container layers and CI caches for LiteLLM 1.82.7 or 1.82.8 and for installs on 24 March 2026 10:39 to 16:00 UTC. Rotate cloud keys SSH keys PyPI or npm tokens Kubernetes service account tokens database passwords AI provider keys reachable from those runners assume theft if temporal overlap exists. Search GitHub organizations for tpcp docs prefix repositories and release assets. Security hardening actions: Move CI to short lived OIDC federation tokens revoke long lived PATs. Pin Trivy and actions by immutable digest. Monitor for secondary use of stolen credentials. Internal security coordination: Notify DevSecOps Cloud Security AppSec Identity Legal if customer data keys exposed. Escalation confirmed use of exfiltrated keys incident declaration. Do this within 24 hours: Complete high privilege secret rotation open tickets for medium privilege backlog with 7 day SLA.
Defender Priority Order Today 1 Cisco ASA and FTD CVE-2026-20349 catalog entry due 14 August unauthenticated edge denial of service outage risk immediate. 2 Metabase CVE-2026-72898 and related catalog entry CVSS 10.0 unauthenticated data plane admin credential theft blast radius. 3 CVE-2026-68820 Windows patch plus Lazarus hunt confirmed APT zero day defense sector targeting rootkit class impact. 4 VMware vCenter CVE-2026-59310 confirmed mass exploitation with persistence tooling. 5 SAP Commerce CVE-2026-58231 CVSS 10.0 unauthenticated remote code execution exploitation not yet confirmed but patch now. 6 LiteLLM credential rotation program delayed reporting long lived secret risk. 7 Microsoft unauthenticated server remote code executions DNS WDS QUIC HPC plus SharePoint July plus August chain verification prevent opportunistic mass exploit post disclosure.
Lazarus Operation Dream Job CVE-2026-68820 Timeline Early 2026 consulted sources begin tracking current Dream Job wave focused on defense and aerospace. 7 July 2026 FudModule related sample compiler timestamp. Early July 2026 exploit assessed used in the wild as part of Dream Job minimum. July 2026 Infection Chain 2 SecurityPDF Enveil impersonation sites observed. 28 July 2026 AFD.sys issue reported to vendor. 31 July 2026 vendor confirms bug. 5 August 2026 vendor assigns CVE-2026-68820. 11 August 2026 vendor ships patch Patch Tuesday consulted sources publish analysis government catalog adds CVE-2026-68820 due approximately 25 August 2026. 12 August 2026 broader secondary amplification and Patch Tuesday coverage.
Metabase CVE-2026-72898 and Related Timeline 6 August 2026 vendor discloses security incident its own Cloud environment attacked using unknown zero day SQL injection. Vendor blocks affected endpoints identifies root cause deploys patch. 10 August 2026 public proof of concept exploit code observed circulating. 11 August 2026 government catalog adds CVE-2026-72898 remediation due 14 August 2026. Related CVE-2026-72899 and CVE-2026-72900 also disclosed and patched in same advisory set. 12 August 2026 continued secondary remediation guidance circulation.
Cisco ASA and FTD CVE-2026-20349 Timeline Earlier August 2026 vendor becomes aware of active exploitation. 11 August 2026 NVD publishes CVE-2026-20349 government catalog adds with due date 14 August 2026 vendor advisory published. 12 August 2026 secondary amplification NVD last modified.
VMware vCenter CVE-2026-59310 Timeline Late July 2026 vendor releases patches and public disclosure. 3 August 2026 first observed victim contact to attacker domains. 12 August 2026 findings published 361 IPs 47 countries reverse ssh persistence. Related scanning for CVE-2026-59309 reported.
SAP Commerce CVE-2026-58231 Timeline 11 August 2026 vendor Security Patch Day August 2026 releases fixes including CVE-2026-58231 and other criticals. 12 August 2026 secondary coverage of CVSS 10.0 Commerce Cloud flaw and guidance.
LiteLLM TeamPCP Impact Reporting Timeline 19 March 2026 malicious Trivy tags and release activity. 24 March 2026 malicious LiteLLM 1.82.7 and 1.82.8 on PyPI approximately 40 minutes from 10:39 UTC. 26 March 2026 CVE-2026-33634 added to government catalog. 31 March 2026 historical supply chain analysis. 2 July 2026 guidance warns of delayed credential abuse. 12 August 2026 dataset and impact reporting 2500 plus organizations reconstructed exposure CVE record lists LiteLLM versions as affected alongside Trivy.
Microsoft August Patch Tuesday Broader Timeline 18 May 2026 SharePoint authentication bypass plus remote code execution chain reported to vendor. July 2026 vendor ships CVE-2026-55040 SharePoint authentication bypass half. 11 August 2026 vendor ships August updates including CVE-2026-63520 remote code execution half and approximately 400 CVEs. 12 August 2026 analyses publish.
Chapter 04 - Detection Intelligence
CVE-2026-68820 afd.sys Use After Free Race to SYSTEM via FudModule Attack vector: Local requires ability to run code as a standard user post phishing initial access. Exploitation mechanism: Concurrent multi thread access to socket state in Windows Ancillary Function Driver afd.sys without proper synchronization use after free kernel read write primitive LPE to SYSTEM. Targets Windows 11 builds 26100 24H2 and 26200 25H2 explicitly in observed sample older builds not targeted by this FudModule build. Observed behavior post exploit FudModule v3.1: Crash dump suppression removal of process thread image notify callbacks object registry callback teardown minifilter removal by altitude kill NT Kernel Logger WFP stage if certain vendor present and another absent ETW provider kill list 94 GUIDs privileged handle forgery two hop spawn services.exe to SYSTEM msiexec.exe Smart App Control VerifiedAndReputablePolicyState set to 0 plus NtSetSystemInformation class 0xA4 option 0x10000000 inject elevated MISTPEN. Vulnerability details: CWE 416 Use After Free. Related historical afd.sys zero days noted. Distinct from other recent. CVE technical context: CVSS 7.0 High vendor Important Exploitability Active. August also patches additional afd.sys elevations of privilege not reported exploited. Patch status: Patched 11 August 2026 Patch Tuesday. Government catalog listed 11 August 2026.
Delivery and implant technical notes: DLL sideload libmupdf.dll beside legitimate signed PDF viewer. SecurityPDF marker string and XOR 0x39 to TEMP new.exe reflective Troy DLL. MISTPEN in memory PE reflective load Graph API OneDrive dead drop AES up down keys. LPE loader GOST CBC plus Base64 Kyber ML KEM key encapsulation export DestroyEnv. Troy 17 commands HTTP C2 handshake expects CONNECTED JSON envelope. RelayShell dual password victim operator modes file channel session id object log backbone URL notification.
CVE-2026-72898 CVE-2026-72899 Unauthenticated Metabase SQL Injection Attack vector: Network unauthenticated HTTP or HTTPS. Exploitation mechanism: SQL injection through password reset API or public cards dashboards field filter parameters into application database via HoneySQL directive structures. Privilege to admin configuration and stored connector credentials. CVE-2026-72900 missing authorization low privileged authenticated user reads entire application database. Observed behavior: Successful exploitation yields administrator level access enabling configuration changes new administrative account or API key creation full read access to any database Metabase is connected to. Vulnerability details: CWE 89. Affects broad on premises version matrix x.58 through x.63. CVSS: 10.0 Critical for primary. Patch status: Fixed builds available catalog 11 August 2026.
CVE-2026-20349 Cisco ASA and FTD SSL VPN Heap Inspection Denial of Service Attack vector: Network unauthenticated to RA SSL VPN service. Exploitation mechanism: Insufficient error checking when processing HTTP requests CWE 244 Heap Inspection unexpected reload. Observed behavior: Device reload or denial of service. No public details on attacker identity targeting or non denial of service payloads. Vulnerable configurations: IKEv2 RA VPN client services SSL VPN webvpn enable zero trust enable. CVSS: 8.6 scope changed availability high. Patch status: Fixed trains published for ASA 9.16 9.18 9.20 9.22 9.23 9.24 and FTD 7.0 7.2 7.4 7.6 7.7 10.0 hotfixes. No workarounds. Catalog due 14 August 2026.
CVE-2026-59310 vCenter Directory Traversal Remote Code Execution Attack vector: Network to vCenter. Exploitation mechanism: Directory traversal arbitrary code execution. Observed behavior: Path traversal telemetry malicious cron reverse ssh outbound C2. Successful compromises not scan only. Related: CVE-2026-59309 unauthenticated authentication bypass in vmdir CVSS 9.8 under increased scanning correlation to same actor not confirmed. Patch status: Patches available pre exploitation wave residual risk unpatched estate.
CVE-2026-58231 SAP Commerce Cloud Data Hub Adapter Attack vector: Network unauthenticated. Exploitation mechanism: Default authentication client abuse insufficient input validation arbitrary code execution. Patch status: Fixed Commerce Cloud releases temporary IP filter on vulnerable endpoint. Exploitation: Not confirmed in consulted sources.
LiteLLM 1.82.7 and 1.82.8 Malicious Package Mechanics Attack vector: Software supply chain PyPI plus CI. Mechanism: litellm_init.pth runs at Python interpreter startup without import harvests secrets encrypts exfils to attacker domain. Upstream: CVE-2026-33634 Trivy ecosystem compromise.
Zoom annotation remote code executions secondary: CVE-2026-53413 CVE-2026-53414 CVE-2026-53415 memory allocation issues remote code execution when attacker and victim share a Zoom meeting. Prioritize client updates but below catalog and APT items.
Lazarus Operation Dream Job Indicators and Infrastructure
Indicators of Compromise
Type Value Context Verdict SHA256 2b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca8 DLL Loader Dropper Pending SHA256 3a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525a DLL Loader Dropper Pending SHA256 92106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1 DLL Loader Dropper Pending SHA256 396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82c DLL Loader Dropper Pending SHA256 f7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4d DLL Loader Dropper Pending SHA256 75b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1 DLL Loader Dropper Pending SHA256 a45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e2 DLL Loader Dropper Pending SHA256 1de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86c DLL Loader Dropper Pending SHA256 4c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d9 DLL Loader Dropper Pending SHA256 29e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a2 DLL Loader Dropper Pending SHA256 4ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105 DLL Loader Dropper Pending SHA256 c2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461 DLL Loader Dropper Pending SHA256 2db25ac41a66aa523c79e23e00443573530dd7bd82b8371bcc87bd7232e141eb MISTPEN Pending SHA256 5278ee922838352f1480a73e971161017d643a80b7ec22bf725897dfd088696d MISTPEN Pending SHA256 b4082d21070d9ddf53fde4ea22524d09e41ec9826ce63cef3c6235e458d21afb MISTPEN Pending SHA256 fb3fc5626f68677fb1269a2fefbe70e719211b4065e836ab92e06a8210139a2d MISTPEN Pending SHA256 ea7056f2bf36c66a61ff787ff5be975a85f534c3c5ca178791dac2504db2c619 MISTPEN Pending SHA256 13d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef79 MISTPEN Pending SHA256 4fd32432341dfcf54d0517a6bbc38e5d265be70933493e4183c2a340cdde9a2d MISTPEN Pending SHA256 4dd792c9f672bbdcc8d363d745994efe90f4ffc5fdc2c059c8e379a48ad6a68a MISTPEN Pending SHA256 ba96c603e44046de703c67b2c3b7e4ca974afef7b437a0244418bc4edc781bb7 MISTPEN Pending SHA256 72dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289 ForestTiger Pending SHA256 231b1ef8b95bf77887d5377e2a60f649035e78f543af1b82877db36a5759d858 ForestTiger Pending SHA256 6da9b1e6f3315ceb77dd14a937a26cc3602bf6a7e2c2ecafb3c65ce5319837be ForestTiger Pending SHA256 a0578a2b7821d7e2c573530648f26d7a0d98b373ab24fb7f0c792736761e542d ForestTiger Pending SHA256 82268052f94df6f4870d02e57b18d4c54136cc7a8c8d80ad162631f99462c943 ForestTiger Pending SHA256 3b6378df8442e63a6ed7317075913e4720847a510d95022d4a8347b2637c245d FudModule Pending SHA256 a673ae661593c0de9bbb815593b816a6853dad6d55ad5042d2ef1875cd13d6e7 PDF Payload Pending SHA256 8ce6c29f92dc45b1474417cbdff4ed0c18e58fa63e3a071ee9f85aa9d2aac07c PDF Payload Pending SHA256 acb97cec84e08b89f41967a24e965d1fd2c51751cef158f7aa35bb4306b87b97 PDF Payload Pending SHA256 3601060c62edeeaa49def6a13be6e126e1024ce011faad4e2d9f585ccf6bd5a6 PDF Payload Pending SHA256 fecf12088843801215898442bd1ff3e266f29d14e29a94780e857f69c4915d6b PDF Payload Pending SHA256 d578c28c9afe7457a0d81f6701332ef8197e8f7468de654935fb29a50ea66459 PDF Payload Pending SHA256 743172aab606974b054a64561534ae66baa3a840657f79d7c6fa18350e8d45d1 SecurityPDF.exe Pending SHA256 db3d69b7eeda2e35e23006bf4b7e206281fce809584207214fc213f9bc30376d SecurityPDF.exe Pending SHA256 590fb6ae19480d694e08ee85859cad8066f2f87e7e5abba2960c6d115e1615d6 Troy Backdoor Pending SHA256 68d4fba7b1300a59cd6212c08910a260cd71b40cd9f51cac933030a68faac0bb Troy Backdoor Pending SHA256 a738059ce07c951c31ab2da3d93d8f69bff32f9b7d933dbf5943441b9cc99075 Troy Backdoor Pending SHA256 21c3ad4838c4324bc5f081021da5fb2e9073d0c9304087811c21eb47c9e22762 RelayShell Pending SHA256 cc4e06aa378a190f71384c03023bb3d18a6d66e297d46701220e132963d2e222 RelayShell Pending Domain envell.xyz SecurityPDF distribution Enveil impersonation Pending Domain enveil.online SecurityPDF distribution Enveil impersonation Pending Domain uxtramine.org Troy C2 related Pending IPv4 135.181.67.203 Troy C2 Pending IPv4 135.181.185.158 Troy C2 Pending
Infrastructure Patterns Compromised Roundcube CVE-2025-49113 plus dark web credentials and PrestaShop as RelayShell nodes at least 17 unique relay PIDs. OneDrive Microsoft Graph API abused as MISTPEN C2 dead drop blends with legitimate cloud traffic. Operator access to RelayShell via shared VPN ExpressVPN observed. SEO ranked impersonation sites separating viewer download from malicious PDF delivery. PDB path residue continuity with historical naming.
Host and file behavioral strings useful as detections not network IOCs Marker This document is encrypted with sumatrapdf reader!!!!!!!!!!!! Drop path TEMP new.exe Sideload name libmupdf.dll FudModule log strings enable_god_mode passed. GetGodMode failed GetSystemHandle passed. ClearVaccine SuspendDefender passed. Troy C2 success banner CONNECTED
LiteLLM TeamPCP Indicators
Type Value Context Verdict Domain models.litellm.cloud Exfil C2 attacker controlled not legitimate LiteLLM Pending Package version LiteLLM 1.82.7 1.82.8 Malicious PyPI releases Malicious vendor project confirmed File pattern litellm_init.pth Python startup persistence execution Pending Repository name tpcp docs docs tpcp tpcp docs prefix Campaign indicator Pending Release tag data timestamp Stolen data release asset pattern Pending CVE CVE-2026-33634 Trivy LiteLLM ecosystem catalog Confirmed catalog March 2026
VMware vCenter Campaign Indicators Tooling reverse ssh open source malicious only in unauthorized install context. Persistence unexpected cron invoking reverse SSH outbound. Victim infrastructure metrics only 361 IPs individual IPs not published not listed. Scanning behaviors for CVE-2026-59309 POST sdk RetrieveServiceContent version probes websso SAML SSO flow walks.
Metabase Cisco SAP Metabase Monitor HTTP access to password reset API paths no public exploit IP set. Cisco No attacker IOC set published detection via device reload telemetry plus crafted HTTP to VPN service. SAP No exploitation IOC set focus on patch verification.
Actor Normalization Evidence reverse ssh appears in both vCenter campaign and historical activity insufficient to merge clusters explicit non correlation statement for related scanning no claim linking to Lazarus or TeamPCP.
T1055 Kernel Tampering Behavioral Cluster Detection Opportunity Lazarus FudModule CVE-2026-68820 Detection engineering opportunities: PDF viewer process loading unusual DLL libmupdf.dll from user writable path. PDF viewer or new.exe in TEMP initiating Microsoft Graph or OneDrive traffic. Sudden disablement of multiple ETW providers minifilter altitude removals NT Kernel Logger termination clustered in seconds. services.exe spawning msiexec.exe then remote thread injection patterns without MSI context. Registry modification of Smart App Control VerifiedAndReputablePolicyState to 0. Immediate detection action within 24 hours: Deploy hash blocklist for all published SHA256 values in EDR or AV. Alert on outbound DNS or HTTP to envell.xyz enveil.online uxtramine.org 135.181.67.203 135.181.185.158. Hunt this week: Hypothesis Dream Job victims exist among employees who received recruiting documents in last 90 days in defense aerospace business units. Evidence target endpoint process trees PDF to DLL sideload OneDrive Graph from non Office processes presence of SecurityPDF binaries.
SIEM field logic product agnostic
Data source requirements: Sysmon events process image load network DNS proxy TLS SNI Windows ETW security auditing if available. Known gaps: MISTPEN fully in memory after initial stage disk hash hunting insufficient alone Graph API C2 requires process context network analytics.
Unauthenticated HTTP Exploit Paths Detection Opportunity Metabase SQL Injection Immediate detection action: WAF or SIEM alert on HTTP requests to Metabase paths containing reset_password with anomalous SQL metacharacters.
Hunt this week: New Metabase admin users connector credential changes large JDBC extract jobs outside business hours.
VPN Control Plane Abuse Detection Opportunity Cisco ASA and FTD CVE-2026-20349 Immediate detection action: Syslog correlation unexpected reload reason plus preceding burst of malformed HTTP to WebVPN portal from single network.
Hunt this week: All unplanned HA failovers on VPN pairs since 1 August 2026 map to patch level.
reverse ssh on Hypervisor Management Detection Opportunity vCenter
Hunt this week: Cron diffs on all vCenter appliances compare to golden image review spool cron and systemd timers.
Python Startup Theft Detection Opportunity LiteLLM
Hunt this week: CI logs 24 March 2026 DNS history for models.litellm.cloud GitHub organization search for tpcp docs patterns cloud trail for keys that existed on runners that day.
Detection Context Quality: Strong for Lazarus rich telemetry. Medium for Metabase Cisco behavior and patch focused. Medium for vCenter tooling based. High confidence package indicators for LiteLLM versions.
No confirmed MITRE technique IDs explicitly mapped in all consulted sources for every cluster. The following mappings are analyst inferred from behaviors documented across consulted sources. They are not source published ATT and CK IDs. Do not treat as vendor validated mappings.
Inferred ID Name Behavioral basis in sources T1566.001 or T1566.002 Phishing Attachment or Spearphishing Link Fraudulent job offers ZIP PDF delivery LinkedIn or messaging assessed Lazarus T1204.002 User Execution Malicious File User opens trojanized PDF viewer or crafted PDF Lazarus T1574.001 Hijack Execution Flow DLL Search Order Hijacking libmupdf.dll sideload beside signed PDF viewer Lazarus T1574.002 DLL Side Loading Legitimate signed PDF viewer side loads malicious libmupdf.dll Lazarus T1027 Obfuscated Files or Information Encrypted ZIP PDF payloads XOR 0x39 AES Graph dead drop Lazarus T1105 Ingress Tool Transfer MISTPEN downloads modules via OneDrive Graph Lazarus T1055 Process Injection Reflective DLL load FudModule inject into SYSTEM process Lazarus T1068 Exploitation for Privilege Escalation CVE-2026-68820 afd.sys LPE Lazarus T1014 Rootkit FudModule tears down callbacks minifilters logger Lazarus T1562.001 or T1562.002 Impair Defenses ETW kill list minifilter removal callback teardown SAC tamper Lazarus T1547 Boot or Logon Autostart Persistence module MISTPEN persistence after reboot Lazarus T1082 or T1057 or T1113 System or Process Discovery Screen Capture GetInfoPlugin PvPlugin OneScreenCapture Lazarus T1071.001 Application Layer Protocol Web Protocols Troy HTTP C2 RelayShell HTTP Lazarus T1102 Web Service OneDrive Graph C2 Lazarus T1505.003 Server Software Component Web Shell RelayShell on Roundcube PrestaShop Lazarus T1190 Exploit Public Facing Application Metabase SQL injection Cisco VPN HTTP vCenter traversal SAP Commerce Roundcube CVE-2025-49113 Multiple T1053.003 Cron Malicious cron for reverse ssh on vCenter VMware T1090 Proxy or multi hop RelayShell backbone relay architecture Lazarus T1195.002 Supply Chain Compromise Compromise Software Supply Chain Trivy to LiteLLM PyPI malicious releases TeamPCP T1552.001 Unsecured Credentials Credentials In Files or Env LiteLLM theft of env vars SSH keys cloud tokens TeamPCP T1499 Endpoint DoS Cisco ASA and FTD reload DoS Cisco
MITRE D3FEND inferred defensive countermeasures D3 PSA Patch Software all catalog and CVSS 10.0 items D3 HAN Harden Network Service Configuration remove internet exposure of Metabase vCenter VPN management D3 IAA Identify Application Agent or software inventory LiteLLM Trivy versions D3 EAL Executable Allowlisting block sideloaded PDF DLLs D3 NTA Network Traffic Analysis Graph API from non Office reverse ssh outbound D3 SCA System Call Analysis or D3 ISVA kernel callback integrity monitoring against FudModule class teardown
Chapter 05 - Governance, Risk & Compliance
Lazarus Dream Job Regulatory and Business Risk Exposure Export control CUI defense program: Organizations in aerospace defense may hold controlled data or national classified adjacent IP. Confirmed Lazarus interest elevates mandatory notification under contractual clauses where applicable validate with counsel. Workforce risk: Recruiting workflows are an attack surface. Governance should require security standards for candidate document handling sandbox no macro or portable viewer exceptions. Board message: Nation state kernel rootkit in recruiting lure equals strategic threat not commodity malware. Patch SLA should be emergency class.
Government Catalog Trio Cisco Microsoft Metabase Compliance Exposure US federal civilian executive branch Binding Operational Directive obligations Cisco due 14 August 2026 Microsoft CVE-2026-68820 due approximately 25 August 2026. Non federal organizations should still adopt catalog as prioritization standard. Evidence to retain: Patch installation logs exception boards incident response hunt results for 3 years or per policy. Metabase: If personal data in connected databases and exploitation occurred notification assessment clock may apply only if personal data breach is confirmed start assessment on suspicion for internet exposed unpatched instances.
VMware vCenter Mass Exploitation Operational Resilience Document management plane isolation control effectiveness or failure for auditors. If tenant or customer VMs potentially accessed prepare customer notification matrices under contracts where applicable.
SAP Commerce CVSS 10.0 Customer Trust and Payment Adjacent Risk Even without confirmed exploitation unauthenticated remote code execution on commerce stack warrants pre breach legal review of customer notification playbooks and payment scope if cardholder data flows touch the same environment. Track note implementation as compliance control evidence.
LiteLLM TeamPCP Third Party and AI Governance Demonstrates AI gateway as identity junction. Update third party risk questionnaires for AI tooling CI dependencies. Prior guidance implies ongoing residual risk board level cyber risk register should track unrotated CI secrets from March 2026 supply chain events as open issue until negative confirmation. Named organization lists in commercial datasets create reputational or legal sensitivity do not treat media lists as breach confirmation without internal validation.
Cross cutting Governance Actions This Week Map each catalog CVE to asset owners and written patch exceptions with expiry less than or equal to due date. Update risk register entries for edge VPN availability business intelligence tool exposure hypervisor management plane nation state local privilege escalation AI tooling supply chain. Tabletop Recruiting PDF to SYSTEM rootkit and Metabase unauthenticated admin to data lake credential theft. For India based defense suppliers victimology includes India align with national incident reporting timelines if compromise confirmed.
Chapter 06 - Adversary Emulation
Lazarus Dream Job Validation and Purple Team Scenarios Objective: Validate detection of sideload to Graph C2 to LPE prep without executing real kernel exploit in production.
ID Scenario ATT and CK inferred Success criteria Safety PT LJ 01 Drop benign DLL named libmupdf.dll beside test PDF viewer in user Downloads launch viewer T1574.001 EDR or SIGMA alert fires Use non malicious DLL isolated lab host PT LJ 02 From non Office process perform OAuth or Graph call pattern to OneDrive test tenant T1102 Network detection on process context Lab credentials only PT LJ 03 Write file TEMP new.exe and execute from parent named SecurityPDF.exe renamed notepad T1204 T1105 Process tree alert Benign payload PT LJ 04 Simulate ETW provider disable burst via documented admin APIs in lab T1562 Telemetry teardown correlation alert Lab only never on production SOC sensors PT LJ 05 Webshell file channel relay on disposable PHP container two passwords session files T1505.003 Webshell YARA plus file integrity alert Isolated VLAN
Do not emulate CVE-2026-68820 exploit code in production. Validate patch presence instead.
Metabase SQL Injection Validation Authenticated scanner or vendor approved detection only against owned instances. Negative test patched instance returns no SQL injection differential on reset password parameter fuzzing in staging. Purple team attempt admin creation via API on staging vulnerable clone behind change window confirm WAF plus patch both catch.
Cisco ASA Denial of Service Validation Do not run denial of service exploits against production VPN. Validate software version greater than or equal to fixed HA failover drill scheduled SIEM reload alert tested with synthetic syslog.
vCenter reverse ssh Validation
LiteLLM Supply Chain Validation
Microsoft DNS WDS QUIC Unauthenticated Remote Code Execution Validation Patch compliance dashboard for hosts with DNS Server or WDS roles. Attack surface verify external port scan should show no WDS TFTP or insecure DNS management exposure.
Purple team calendar suggested Day 0 to 1 Patch validation automation for catalog CVEs. Day 2 to 3 Lazarus delivery detections PT LJ 01 to 03. Day 4 vCenter reverse ssh lab. Day 5 Metabase staging plus LiteLLM inventory certification. Week 2 FudModule class defense impairment detections in isolated range.
| Factor | Contribution | Notes | | Highest weight sources present | Base high | Government catalog authoritative plus elevated technical deep dive plus vendor statements via multiple amplifiers | | Corroboration bonus | Positive | Lazarus exploitation confirmed across multiple consulted sources | | Cisco and Metabase catalog status | Positive | Multi sourced | | Deductions | Modest negative | VMware campaign details primarily single incident response firm amplified secondary LiteLLM scale metrics single firm reconstructed exposure with explicit caveat no source mapped MITRE IDs attribution for CVE-2026-68820 rests on primary research Microsoft did not publicly attribute | | Overall | 84 | Not inflated to 90 plus because actor gaps remain on Cisco Metabase VMware clusters and scale claims need verification Floor ceiling respected single source claims kept appropriately bounded |
Intelligence gaps No public exploit packet captures for Cisco CVE-2026-20349 attacks. No named Metabase victim organizations. VMware actor identity unconfirmed victim IP list unpublished. SAP exploitation status unknown. Exact Microsoft KB article numbers vary by OS build in secondary sources validate in vendor update guide before change tickets. Zoom proof of concept depth not fully detailed beyond summary.
