Last Updated On

CCTTII--22002266--00881133
IInnffoorrmmaattiioonnaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

The Job PDF That Bought SYSTEM Access While Firewalls Reloaded

A recruiter message and a polished PDF were all it took for Lazarus to land SYSTEM on Windows 11 through an afd.sys use after free that had been live since July. The same forty eight hour window also forced federal clocks on a Cisco ASA FTD VPN reload bug and a Metabase SQL injection while a July SharePoint JWT bypass suddenly saw active scanning after a public proof of concept.

Separate from the nation state activity a CVSS 9.8 vCenter path traversal is already being used to plant reverse SSH persistence five days after its patch a Magento session hijack is under active probing and a year long campaign is quietly emptying misconfigured Salesforce and ServiceNow guest portals. Central European banks are facing a new NFC relay malware that clones contactless cards during a live phone call and a hardware wallet maker disclosed that its shipping partner was breached exposing order data for nearly fourteen thousand customers.

None of these threads share an operator yet all of them demand action before the next calendar deadline. The full technical package contains the hashes the detection logic and the exact questions boards should be asking tonight.

9.1

CVSS Score

45

IOC Count

18

Source Count

68

Confidence Score

CVEs

CVE-2026-68820 CVE-2026-20349 CVE-2026-72898 CVE-2026-55040 CVE-2025-49113 CVE-2026-59310 CVE-2026-71362

Actors

Lazarus Group, Storm 1175, Under Attribution

Sectors

Defense, Aerospace, Aviation, Technology, Government, Analytics BI, IT Cloud infrastructure, Network Perimeter security, E commerce Retail, Cross sector SaaS, Financial services Banking, Cryptocurrency hardware

Regions

France, Germany, India, Brazil, Western Europe, South America, United States, Global, Czechia, Slovakia, Slovenia, UK, Sweden, Colombia, Italy, Portugal

Chapter 01 - Executive Overview

The window is not a recap of Patch Tuesday. It is the 24 hours after the patch dropped when Lazarus tradecraft three CISA KEV rows a public SharePoint PoC a reported vCenter RCE Adobe session hijack attempts a long running SaaS guest data harvest NFC relay fraud and a third party shipping breach all landed on the same desk.

Check Point Operation Dream Job write up carried into this window by BleepingComputer and The Hacker News is the item that should move a SOC tonight. North Korea linked operators are not spraying a kernel bug at the internet. They are walking defense aerospace and aviation staff through a fake recruiter conversation a trojanized PDF viewer and then a use after free in afd.sys that consulted sources say has been live since early July. Microsoft patched it on 11 Aug as CVE-2026-68820. CISA put it in KEV. The exploit is local. The access is social. The rootkit is FudModule 3.1. The new implant is Troy. That is a complete espionage stack not a CVSS argument.

Two other KEV rows sit on internet edges and do not need a recruiter. CVE-2026-20349 lets anyone who can reach Cisco ASA FTD Remote Access SSL VPN send one crafted HTTP request and reload the box. Cisco confirmed exploitation this month and published no actor no targets and no IOCs. Federal due date is 14 Aug. CVE-2026-72898 is unauthenticated SQL injection on Metabase reset password CVSS 4.0 10.0 already used against Metabase Cloud. Cloud is patched. Self hosted is not automatically safe. Federal due date is also 14 Aug.

SharePoint is the opportunistic third rail. CVE-2026-55040 was patched in July. Rapid7 JWT forgery PoC landed this week. KEVIntel counted eight of twelve known attempts on 12 to 13 Aug from eight IPs in Hong Kong Japan the Netherlands Taiwan and the United States. Nobody has named the operators. Treat it as commodity exploitation of a July patch not a Lazarus overlay. There is no evidence these problems are one campaign.

A directory traversal vulnerability in vCenter Syslog server CVE-2026-59310 CVSS 9.8 patched 29 Jul 2026 is reportedly being exploited by a suspected APT to deploy a reverse SSH persistence tool. The claim originates from IR firm reporting corroborated via VulnCheck own KEV listing. CVE-2026-59310 is not in the CISA KEV catalog so treat as reported but not government confirmed. Over 1100 vCenter instances are internet exposed per telemetry.

CVE-2026-71362 CVSS 9.1 an incorrect authorization flaw enabling session hijacking between Magento Adobe Commerce accounts is seeing exploitation attempts blocked by Sansec WAF within a day of patch release. Adobe reports no confirmed successful compromise. No user interaction is required.

An unattributed campaign active since March 2025 is quietly harvesting data exposed via misconfigured guest anonymous access on Salesforce Experience Cloud and ServiceNow Service Portal deployments. No CVE or patch the root cause is customer side misconfiguration.

Group IB documented a live call fraud chain pairing SpyNote RAT with new NFC relay malware WindRelay cloning a tapped contactless card for use at a payment terminal within minutes. Confirmed victims in Czechia Slovakia and Slovenia.

Trezor disclosed that shipping vendor ShipMonk was breached exposing order data for 13689 customers across 7 countries. ShipMonk told customers the intrusion traces to a Metabase vulnerability plausibly the maximum severity Metabase issue reported exploited in early August 2026 though this link is not confirmed by an official advisory. Trezor own infrastructure firmware and devices were not affected.

What leadership should fund in the next 48 hours is dull and expensive August Windows updates on defense adjacent endpoints Cisco RA VPN hotfixes before Friday KEV clock Metabase point releases plus session wipe a SharePoint July patch audit that assumes the PoC is now a scanner default vCenter isolation and post compromise hunting Adobe session integrity hardening guest access configuration reviews on Salesforce and ServiceNow customer and employee advisories on NFC fraud and phishing defense for the Trezor customer set.

Chapter 02 - Threat & Exposure Analysis

When the recruiter is the exploit chain Consulted sources are explicit this Dream Job wave is affiliated to Lazarus and aimed at defense especially aerospace aviation surveillance sensors drones and robotics. Confirmed victim geography in the research is France Germany India and Brazil with South America called out as reach and Western Europe as successful targeting. In at least one case a compromised French organization was reused to spear phish the next set of victims which is how you borrow someone else mail reputation.

Two infection chains run in parallel. The older one is an encrypted zip signed PDF viewer malicious libmupdf.dll decoy PDF. Sideload displays the job description and reflectively runs MISTPEN Mandiant 2024 Graph API OneDrive downloader. MISTPEN then stages GetInfoPlugin PvPlugin OneScreenCapture a persistence module the LPE loader FudModule and ForestTiger ScoringMathTea. The newer chain is SecurityPDF a trojanized MuPDF viewer distributed from Enveil impersonation sites that consulted sources saw ranking at the top of search. The viewer looks for the ASCII marker This document is encrypted with sumatrapdf reader!!!!!!!!!!!! XOR decodes with 0x39 writes TEMP new.exe and reflectively loads Troy a previously undocumented 17 command DLL backdoor.

CVE-2026-68820 is the privilege hinge not the front door. Consulted sources sample Afd4Eop12_x64.dll compiles to 7 Jul 2026 22 07 44 UTC checks for Windows 11 builds 26100 and 26200 races afd.sys socket state across threads and turns the use after free into a kernel read write and SYSTEM. Disclosure 28 Jul to MSRC confirmed 31 Jul CVE 5 Aug patch 11 Aug. This is Lazarus second afd.sys zero day after CVE-2024-38193. It is not CVE-2025-60719. FudModule 3.1 keeps the v3 telemetry teardown notify callbacks minifilters NT Kernel Logger 94 ETW GUIDs crash dump suppression WFP stage when Kaspersky is present and Symantec is not and adds Smart App Control tamper SYSTEM msiexec.exe sets VerifiedAndReputablePolicyState to 0 and calls NtSetSystemInformation class 0xA4 0x10000000. Dedicated Defender suspend and AhnLab PPL strip are gone. Targeting is newer Windows only.

C2 is stolen legitimacy. ForestTiger historically lived on compromised WordPress and SharePoint. This wave prefers Roundcube often CVE-2025-49113 after leaked credentials plus some PrestaShop all hosting RelayShell a PHP relay that is not a classic command shell. Seventeen unique RelayShell IDs were recovered. Operators hit the panel through ExpressVPN. Troy talks HTTP wants a CONNECTED banner then JSON to channel msg base64. The LPE loader adds GOST CBC and ML KEM Kyber on top of MISTPEN AES Graph channel. That is not noisy malware. That is someone who expects a defense contractor SOC to be awake.

Three KEVs and a PoC that did not wait CISA KEV additions dated 11 Aug became the operational drumbeat of this window. CVE-2026-68820 due 25 Aug. CVE-2026-20349 and CVE-2026-72898 due 14 Aug. KEV means exploitation is confirmed. It does not mean the three bugs share an actor.

Cisco CVE-2026-20349 is CWE 244 heap inspection insufficient HTTP error checking on Remote Access SSL VPN. Unauthenticated no user interaction device reload availability only. Exposed if IKEv2 client services webvpn enable or FTD zero trust enable is on. FMC is not affected. No workaround. Hotfixes exist for ASA 9.16 to 9.24 and FTD 7.0 7.2 7.4 7.6 7.7 10.0. Cisco learned of exploitation in August 2026 found the bug internally and also credited Valerio Brussani. Actor victims and IOCs unpublished. Under Attribution.

Metabase CVE-2026-72898 is unauthenticated SQL injection via the password reset database endpoint. NVD remote attacker injects SQL through reset password and gains administrator on the connected instance. Vendor versions 1.58 and above Cloud was hit as a zero day endpoints blocked Cloud already patched. Self hosted minimum safe points include 0.58.24 0.59.21 0.60.17 0.61.11 0.62.9 0.63.5. Below 58 is not vulnerable. Compromise pattern in logs POST api session reset password 400 then GET api user current 200. After admin the vendor lists config change theft of stored database credentials read of connected warehouses and export. Actor Under Attribution.

SharePoint CVE-2026-55040 is July JWT authentication bypass CWE 1390 on Subscription Edition 2019 and 2016. SharePoint Online is not in the Rapid7 THN affected set. Rapid7 chain outer JWT alg none actor token x5t set to SharePoint own STS thumbprint certificate accepted even when not in TrustedSecurityTokenServices non empty dummy signature such as AAAA never verified. Result unauthenticated impersonation of a site user or administrator file disclose and modify not availability. Microsoft the authentication feature could be bypassed as this vulnerability allows impersonation. Defused Cyber says operators are using Rapid7 PoC. KEVIntel 12 attempts since 19 Jul eight on 12 to 13 Aug eight IPs five geographies. THN notes this is the fifth SharePoint bug exploited in 2026 after CVE-2026-45659 CVE-2026-56164 CVE-2026-58644 and CVE-2026-50522. Actor Under Attribution. Do not weld this to Lazarus because ForestTiger has historically used compromised SharePoint servers. That is infrastructure reuse in a different campaign not evidence that Dream Job is forging these JWTs.

SANS Stormcast on 13 Aug flagged the SharePoint JWT PoC and ShieldBreak a researcher PoC claiming a Defender patch bypass for CVE-2026-50656. ShieldBreak is not KEV and is not confirmed in the wild in consulted sources this window. Leave it in the lab queue.

CVE-2026-59310 Path Traversal to Unauthenticated RCE in vCenter Syslog Server The flaw CWE 22 lets a network adjacent unauthenticated attacker traverse file paths handled by vCenter Syslog service to execute arbitrary code. Broadcom patched it in VMSA 2026 0006 29 Jul 2026 alongside auth bypass CVE-2026-59309. QUIRSO IR engagement traced first attacker C2 contact to 3 August 2026 a five day patch to exploit gap indicating rapid weaponization. Post exploitation reportedly includes cron based persistence and a reverse SSH tool for durable access. EPSS sits near 1.1 percent illustrating that EPSS under predicts real world exploitation for appliance class RCEs. Attribution suspected APT is asserted without a named group Under Attribution.

CVE-2026-71362 Cross Account Session Confusion in Adobe Commerce Magento The vulnerability incorrect authorization CWE 863 allows an unauthenticated remote attacker to switch an active customer session to a different arbitrary customer account without credentials per Sansec patch diff analysis Magento mishandles customer identity binding within session state. Affects Adobe Commerce Commerce B2B Magento Open Source 2.4.6 to 2.4.9. Sansec Shield WAF reports blocked exploitation attempts under 24 hours after the 11 August patch Adobe states it is not aware of successful exploitation do not overstate exploitation status as fully confirmed.

City Forum Unauthenticated Harvesting of Salesforce and ServiceNow Guest Data No vendor vulnerability is involved. The campaign abuses legitimately configured but over permissive guest anonymous access on Salesforce Experience Cloud sites and ServiceNow Service Portals to enumerate and exfiltrate exposed records. Linked infrastructure has reportedly been active since March 2025. No actor name CVE or IOC set is publicly attributed researchers explicitly decline attribution.

WindRelay SpyNote Live Call NFC Relay Fraud Chain Group IB documents a chain starting with a vishing call impersonating bank staff tricking the victim into sideloading a personalized SpyNote RAT build which then sideloads WindRelay a purpose built NFC relay malware that captures the live EMV APDU exchange when the victim taps their card against the phone streaming it to an attacker device that emulates the card at a POS terminal or ATM reportedly completing card clone to cash out in as little as 13 minutes. 23 related samples Nov 2025 to Jul 2026 and 4 C2 IPs identified but not published. Confirmed geography Czechia Slovakia Slovenia. WindRelay was first seen August 2025 this is the first detailed public writeup of the SpyNote pairing.

Trezor ShipMonk Third Party Fulfilment Breach Exposing Order PII ShipMonk notified Trezor on about 10 August 2026 of unauthorized access to systems holding order data. Trezor own infrastructure firmware and devices were not affected no private keys seeds or funds exposed. 11742 customers had full exposure name email phone address 1947 had partial exposure name city email 13689 total orders placed 10 May to 8 August 2026 across US UK Sweden Colombia Brazil Italy Portugal. ShipMonk told customers the intrusion involved a Metabase vulnerability which if it is the maximum severity Metabase SQL injection reported exploited 8 August 2026 would place this in a broader exploitation wave this specific linkage is not confirmed by an official advisory.

Chapter 03 - Operational Response

Patch the kernel then hunt the recruiter

Apply the 11 Aug Windows security updates that include CVE-2026-68820 before you argue about CVSS 7.0. The score is local high complexity. The operator already has a user who opened a job PDF. Hunt defense aerospace and aviation endpoints for SecurityPDF libmupdf.dll beside a signed viewer TEMP new.exe msiexec.exe spawned from services.exe after a socket heavy burst and Graph API traffic from those processes. Pull Check Point hash set into EDR allow block. Tell recruiting and program management staff that Lockheed Martin and Enveil job PDFs arriving outside the ATS are a security event.

Kill the VPN reload before Friday

Inventory every internet facing ASA FTD. If RA SSL VPN IKEv2 client services or FTD ZTNA is enabled you are in the blast radius. There is no workaround. Install Cisco published hotfixes. FCEB due date is 14 Aug 2026. Watch for unexplained reloads and VPN drops Cisco released no exploit packet signatures. Confirm FMC is out of scope and do not waste the change window there.

Assume self hosted Metabase was scanned

Upgrade to the vendor minimum safe point release. If api session reset password is reachable treat that as internet exposure. After upgrade delete core session rows review API keys and admin accounts rotate every connected warehouse credential and grep ingress logs for the 400 then 200 pattern. Temporary control if you cannot patch block the reset password endpoint. Cloud customers are already on the fixed build per Metabase.

Treat July SharePoint as unpatched until proven

Confirm on prem Subscription Edition 2019 2016 are on the July 2026 SharePoint updates for CVE-2026-55040. Hunt IIS ULS for Bearer tokens with alg none or garbage signatures against vti bin and other S2S endpoints. Rapid7 PoC enumerates users by SID and hunts a site admin. If you still have an unauthenticated admin path isolate the farm.

VMware vCenter Isolation and Post Compromise Hunting

Confirm patch status against VMSA 2026 0006 if unpatched treat vCenter as compromised by default given the 5 day patch to exploit gap. Restrict network reachability to the vCenter Syslog service to trusted management subnets only over 1100 exposed instances identified. Hunt for unauthorized cron entries and unexpected outbound SSH tunnels reverse ssh from the vCenter appliance host. Engage IR support for any appliance showing signs of compromise on or after 3 August 2026.

Adobe Commerce Magento Session Integrity Hardening

Apply Adobe 11 August 2026 security update for Commerce Commerce B2B and Magento Open Source without delay. Deploy update WAF rules Sansec Shield or equivalent to detect anomalous session customer ID mismatches. Audit for accounts with session activity inconsistent with the authenticated user history since 11 August.

City Forum Guest Access Configuration Review

Audit Salesforce Experience Cloud guest user profiles and sharing rules for over permissive object field access. Audit ServiceNow Service Portal anonymous guest widget and record access ACLs. Review access logs for unauthenticated high volume enumeration patterns against portal endpoints since March 2025.

WindRelay SpyNote Customer and Employee Advisory

Financial institutions should brief customers legitimate bank staff never ask you to install an app or tap your card against your phone during a call. Banks in Czechia Slovakia Slovenia should treat this as an active regional fraud pattern requiring fraud team alerting. Enterprises should block sideloading of unsigned APKs on corporate managed Android devices via MDM policy.

Trezor ShipMonk Customer Notification and Phishing Defense

Affected Trezor customers orders 10 May to 8 Aug 2026 7 countries should treat unsolicited contact referencing their order number as phishing. Trezor states devices firmware and private keys are unaffected do not re seed or transfer funds based on unsolicited security prompts. Metabase users should verify patch status against the 8 August 2026 zero day disclosure independent of this breach.

Do not merge the incidents

Multiple problems multiple tickets multiple owners. Dream Job is HR plus EDR plus webmail. Cisco is network. Metabase is data platform. SharePoint is collaboration. VMware is virtualization. Adobe is e commerce. City Forum is SaaS configuration. WindRelay is consumer fraud. Trezor is supply chain. Combining them into one August exploitation incident will hide the French mail relay hunt under a firewall change request.

Early 2026 Consulted sources begin tracking this Dream Job wave against global defense aerospace and aviation. 2025 and earlier ESET and others documented trojanized PDF viewers in prior Dream Job waves MISTPEN documented by Mandiant in 2024 FudModule lineage to about 2021 prior afd.sys zero day CVE-2024-38193 in 2024. 7 Jul 2026 22 07 44 UTC Compiler timestamp on consulted sources Afd4Eop12_x64.dll. Early Jul 2026 Consulted sources CVE-2026-68820 used in the wild in Dream Job SecurityPDF Troy chain observed. 19 Jul 2026 Earliest KEVIntel hit on CVE-2026-55040 pre PoC low volume. 28 Jul 2026 Consulted sources report the afd.sys bug to MSRC. 29 Jul 2026 Broadcom publishes VMSA 2026 0006 CVE-2026-59310 59309 patched. 31 Jul 2026 Microsoft confirms the bug. 3 Aug 2026 First reported attacker C2 contact against exploited vCenter systems. 5 Aug 2026 CVE-2026-68820 assigned. On or before 6 Aug 2026 Metabase detects Cloud abuse of the then unpatched reset password SQLi blocks endpoints patches Cloud. 6 Aug 2026 Metabase publishes the self hosted upgrade advisory. 8 Aug 2026 Metabase max severity zero day disclosed as exploited in the wild. 10 Aug 2026 NVD publishes CVE-2026-72898. About 10 Aug 2026 ShipMonk notifies Trezor of unauthorized access. 11 Aug 2026 Microsoft August Patch Tuesday ships CVE-2026-68820 Consulted sources publish Shattering the Dream Cisco publishes the ASA FTD advisory CISA adds CVE-2026-68820 CVE-2026-20349 and CVE-2026-72898 to KEV NVD KEV date Cisco due 14 Aug Metabase due 14 Aug Windows due 25 Aug Adobe Patch Tuesday ships fix for CVE-2026-71362. 11 Aug 2026 outside this window start Initial Cisco Patch Tuesday news hits used only as provenance. 12 Aug 2026 in window BleepingComputer and The Hacker News carry Lazarus CVE-2026-68820 The Hacker News and SecurityWeek carry Cisco exploited in the wild KEV NVD last modified stamps on 68820 20349 72898 Rapid7 PoC timing cited as earlier this week City Forum SecurityWeek Register WindRelay SpyNote Group IB Adobe Commerce attempts Sansec publicly reported. 12 to 13 Aug 2026 KEVIntel eight of twelve SharePoint CVE-2026-55040 attempts. 13 Aug 2026 The Hacker News SharePoint exploitation after PoC SANS Stormcast SharePoint JWT PoC and ShieldBreak NVD last modified CVE-2026-55040 Security Affairs unscored repeats the KEV trio VMware vCenter active exploitation reporting surfaces broadly Trezor publicly discloses ShipMonk breach scope 13689 customers. 14 Aug 2026 CISA KEV due date for CVE-2026-20349 and CVE-2026-72898. 25 Aug 2026 CISA KEV due date for CVE-2026-68820.

Chapter 04 - Detection Intelligence

CVE-2026-68820 and the Dream Job stack Microsoft via NVD use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. CWE 416. Consulted sources high level mechanism afd.sys keeps per socket state two unsynchronized code paths can run on that state when several threads touch a socket during creation access one path uses memory the other already freed the module converts that UAF into a kernel read write primitive then SYSTEM. The in campaign loader is Afd4Eop12_x64.dll export path into FudModule string enable_god_mode passed. Minimum build gate Windows 11 26100 24H2 also 26200 25H2. Not the same bug as CVE-2025-60719. Local only. No user interaction at exploit time. Initial access is already won.

DLL sideload chain encrypted archive legitimate signed viewer libmupdf.dll encrypted PDF named payload decoy rendered MISTPEN in memory. MISTPEN uses Microsoft Graph against attacker OneDrive files AES with separate up down keys reflective PE DLL load. Plugins observed

GetInfoPlugin Release_GetInfoPlugin_x64.dll NetGetJoinInformation computer name user OS build returned as one wide string. PvPlugin Release_PvPlugin_x64.dll same plus PID PPID create time domain user image name. OneScreenCapture OneScreenCapture64.dll virtual desktop via USER32 GDI JPEG Base64 wide string. Persistence module on disk install run after reboot. Exact autorun primitive insufficient data. LPE loader RPC buffer through MISTPEN extra GOST CBC with random 16 byte session key prepended Base64 four stage handshake fingerprint OS build security products request four public keys ML KEM Kyber encapsulate download encrypted LPE run export DestroyEnv status messages home.

FudModule 3.1 post exploit consulted sources vs Gen Digital v3 crash dump suppression first strip process thread image notify object and registry callbacks minifilter removal by altitude kill NT Kernel Logger 94 ETW provider GUIDs matching Gen first 94 of 95 same order driver keep kill engine privileged handle forgery two hop services.exe SYSTEM msiexec.exe log strings GetGodMode failed GetSystemHandle passed. CreateRemoteProcess passed. RemoteDllExecute passed. ClearVaccine. New Smart App Control remote stub in msiexec sets VerifiedAndReputablePolicyState to 0 NtSetSystemInformation class 0xA4 option 0x10000000 in place CI policy reload. Removed dedicated MsMpEng.exe suspend orphaned string SuspendDefender passed. AhnLab asdsvc.exe PPL strip. Defender still blinded only by the generic suppressor. WFP stage still keyed to Kaspersky present Symantec absent that is a product check not Kaspersky attribution.

SecurityPDF chain trojanized MuPDF hooks File Open and drag drop marker This document is encrypted with sumatrapdf reader!!!!!!!!!!!! XOR key 0x39 drop TEMP new.exe reflective Troy. Sites envell.xyz enveil.online uxtramine.org. Consulted sources Enveil was impersonated not compromised. Troy 64 bit DLL PDB E HK Tool_Module Troy_Handle 1Troy_Create_Dll_Tool x64 Release Test_Dll.pdb three C2 URL port tuples HTTP connect expect CONNECTED challenge response register user profile dir account Windows version local IPv4 CWD Base64 tasks with plaintext prefixes replies to channel msg base64 chunked if large. Seventeen commands cover recon file upload download delete archive exfil hidden command execution remote process kill in memory DLL inject beacon config changes. Exact opcode table insufficient data.

RelayShell PHP victim vs operator passwords on POST config file substitution ciphered with backbone URL PID victim mode opens session and POSTs to backbone operator mode session mgmt connectivity upload delete logs send receive via session_id object.log where object 1 victim 2 operator. Not a bind shell. Compromised Roundcube often via leaked creds then CVE-2025-49113 authenticated PHP object deserialization RCE. Also PrestaShop. Seventeen PIDs. ExpressVPN in front.

ForestTiger hashes published it is the long haul RAT on the sideload path after SYSTEM MISTPEN. No new ForestTiger protocol decode in this window beyond compromised CMS webmail as C2.

CVE-2026-20349 Cisco RA VPN NVD Cisco insufficient error checking on HTTP to Remote Access SSL VPN unauthenticated remote crafted request unexpected reload DoS. CWE 244. Vulnerable configs IKEv2 RA VPN with client services SSL VPN webvpn enable iface FTD ZTNA zero trust enable. Requires SSL listen sockets. FMC not affected. No workaround. Fixed trains reported by THN from the advisory ASA 9.16 9.18 9.20 9.22 9.23 9.24 example fixed builds 9.20.4.235 9.22.3.191 9.23.1.211 9.24.1.221 9.16 9.18 strings in secondary text were garbled and should be taken from Cisco own matrix not retyped here as gospel. FTD hotfixes named for 7.0 GC 7.2 HM 7.4 HK 7.6 DD 7.7 AN 10.0 S R. Not RCE in any consulted sources. Not paired with a second Cisco bug in this window. Exploit packet not confirmed.

CVE-2026-72898 Metabase CWE 89. Unauthenticated SQL injection into the application database through the password reset path. NVD names reset password. Vendor hunt path is api session reset password. After SQLi administrator on the Metabase instance then stored connector credentials and warehouse data. Cloud already patched. Self hosted must move to listed point releases. Workaround block the endpoint. No public exploit code was retrieved from consulted sources in this window. No actor.

CVE-2026-55040 SharePoint JWT CWE 1390 weak authentication. Classes SPJsonWebSecurityTokenHandlerV2 SPJsonWebSecurityBaseTokenHandlerV2. Four weakness chain Rapid7 via THN 1 outer header alg none so no outer signature 2 actor token x5t farm STS cert thumbprint key resolved without proving possession 3 resolved cert need not be in TrustedSecurityTokenServices 4 actor signature is any non empty blob and is not verified. PoC uses the forged Bearer token to query the domain controller enumerate SIDs locate a site admin. Impact per Microsoft disclose files modify data no availability hit. On prem only in cited research. Public PoC Rapid7 github.com sfewer r7 CVE-2026-55040. Exploitation after PoC is telemetry from KEVIntel via THN not a named incident report.

CVE-2026-59310 VMware vCenter Path traversal CWE 22 in Syslog server allows unauthenticated RCE. Post exploitation includes reverse SSH persistence and cron based persistence. Over 1100 internet exposed instances. Five day patch to exploit gap.

CVE-2026-71362 Adobe Commerce Magento Incorrect authorization CWE 863 allows unauthenticated session switch to arbitrary customer account. Affects 2.4.6 to 2.4.9. Attempts blocked by WAF no confirmed successful exploitation.

City Forum Abuses over permissive guest anonymous access on Salesforce Experience Cloud and ServiceNow Service Portal. Active since March 2025. No CVE.

WindRelay SpyNote Vishing to SpyNote RAT sideload then WindRelay NFC relay captures live EMV APDU streams to attacker emulator. Cash out in as little as 13 minutes. 23 samples 4 C2 IPs unpublished. Czechia Slovakia Slovenia.

Trezor ShipMonk Third party breach of order data 13689 customers 7 countries. Possible Metabase link not confirmed. Devices keys unaffected.



All hashes are SHA 256 as published by Check Point Research. Verdict column is vendor published only. Independent enrichment insufficient data.

DLL loader dropper 2b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca8 3a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525a 92106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1 396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82c f7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4d 75b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1 a45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e2 1de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86c 4c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d9 29e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a2 4ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105 c2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461

MISTPEN 2db25ac41a66aa523c79e23e00443573530dd7bd82b8371bcc87bd7232e141eb 5278ee922838352f1480a73e971161017d643a80b7ec22bf725897dfd088696d b4082d21070d9ddf53fde4ea22524d09e41ec9826ce63cef3c6235e458d21afb fb3fc5626f68677fb1269a2fefbe70e719211b4065e836ab92e06a8210139a2d ea7056f2bf36c66a61ff787ff5be975a85f534c3c5ca178791dac2504db2c619 13d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef79 4fd32432341dfcf54d0517a6bbc38e5d265be70933493e4183c2a340cdde9a2d 4dd792c9f672bbdcc8d363d745994efe90f4ffc5fdc2c059c8e379a48ad6a68a ba96c603e44046de703c67b2c3b7e4ca974afef7b437a0244418bc4edc781bb7

ForestTiger 72dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289 231b1ef8b95bf77887d5377e2a60f649035e78f543af1b82877db36a5759d858 6da9b1e6f3315ceb77dd14a937a26cc3602bf6a7e2c2ecafb3c65ce5319837be a0578a2b7821d7e2c573530648f26d7a0d98b373ab24fb7f0c792736761e542d 82268052f94df6f4870d02e57b18d4c54136cc7a8c8d80ad162631f99462c943

FudModule 3b6378df8442e63a6ed7317075913e4720847a510d95022d4a8347b2637c245d

PDF payload a673ae661593c0de9bbb815593b816a6853dad6d55ad5042d2ef1875cd13d6e7 8ce6c29f92dc45b1474417cbdff4ed0c18e58fa63e3a071ee9f85aa9d2aac07c acb97cec84e08b89f41967a24e965d1fd2c51751cef158f7aa35bb4306b87b97 3601060c62edeeaa49def6a13be6e126e1024ce011faad4e2d9f585ccf6bd5a6 fecf12088843801215898442bd1ff3e266f29d14e29a94780e857f69c4915d6b d578c28c9afe7457a0d81f6701332ef8197e8f7468de654935fb29a50ea66459

SecurityPDF.exe 743172aab606974b054a64561534ae66baa3a840657f79d7c6fa18350e8d45d1 db3d69b7eeda2e35e23006bf4b7e206281fce809584207214fc213f9bc30376d

Troy 590fb6ae19480d694e08ee85859cad8066f2f87e7e5abba2960c6d115e1615d6 68d4fba7b1300a59cd6212c08910a260cd71b40cd9f51cac933030a68faac0bb a738059ce07c951c31ab2da3d93d8f69bff32f9b7d933dbf5943441b9cc99075

RelayShell 21c3ad4838c4324bc5f081021da5fb2e9073d0c9304087811c21eb47c9e22762 cc4e06aa378a190f71384c03023bb3d18a6d66e297d46701220e132963d2e222

Domains and IPs SecurityPDF Troy C2 per consulted sources envell.xyz enveil.online uxtramine.org 135.181.67.203 135.181.185.158

Host artifacts and infrastructure fingerprints libmupdf.dll next to a signed PDF viewer in a user writable directory TEMP new.exe spawned by SecurityPDF Marker ASCII This document is encrypted with sumatrapdf reader!!!!!!!!!!!! XOR key 0x39 on embedded PDF payloads Internal names Release_GetInfoPlugin_x64.dll Release_PvPlugin_x64.dll OneScreenCapture64.dll Afd4Eop12_x64.dll PDB E HK Tool_Module Troy_Handle 1Troy_Create_Dll_Tool x64 Release Test_Dll.pdb HTTP banner check CONNECTED JSON C2 envelope to plus Base64 msg Graph API OneDrive file exchange from a PDF viewer or rundll like unsigned module RelayShell session files session_id1.log session_id2.log on compromised Roundcube WordPress PrestaShop Smart App Control tamper VerifiedAndReputablePolicyState 0 plus NtSetSystemInformation 0xA4 0x10000000 Two hop spawn services.exe SYSTEM msiexec.exe

Actor normalisation Consulted sources cluster this wave to Lazarus via FudModule lineage MISTPEN ForestTiger Dream Job lure design PDB Troy reuse versus ESET prior E Work Troy path and the second afd.sys zero day pattern. Microsoft public KEV Patch Tuesday language confirms exploitation of CVE-2026-68820 not the actor name in sources retrieved this window. Cisco Metabase and SharePoint clusters have no actor normalisation evidence. VMware Adobe City Forum WindRelay Trezor clusters remain under attribution or unattributed.

Shared infrastructure clues Compromised Roundcube WordPress SharePoint PrestaShop as ForestTiger RelayShell relays SEO ranked impersonation domains ExpressVPN for operator access one breached French organisation reused as a mailer. No overlap published between those relays and the Cisco Metabase SharePoint JWT VMware Adobe City Forum or WindRelay activity.

No concrete IOC values hashes IPs domains were published in the sources reviewed for VMware Adobe City Forum WindRelay or Trezor clusters. Group IB references 23 WindRelay samples and 4 C2 IPs without disclosing values. VulnCheck paid feed reportedly includes weaponized exploit PCAP and Snort Suricata Sigma rules for CVE-2026-59310 not disclosed in free tier reporting. Insufficient data for IOC enumeration on those clusters.

Collection gaps Cisco published no exploit PCAP or IPS signature in the retrieved advisory coverage. Metabase gave an application log pattern only. SharePoint hunt depends on IIS ULS retaining Authorization headers. FudModule job is to delete the telemetry you wanted. If ETW providers and minifilters die mid incident the absence is the signal. VMware Adobe City Forum WindRelay and Trezor clusters published no concrete detection signatures in free sources.

Threat hunting hypotheses Defense sector endpoint opened a recruiter PDF then a PDF viewer loaded libmupdf.dll from the same folder then Graph API calls began. SecurityPDF wrote TEMP new.exe within seconds of opening a PDF containing the Sumatra marker. Low privilege process issued a burst of AFD socket IOCTLs then services.exe created SYSTEM msiexec.exe then Smart App Control policy flipped to 0. Internet facing ASA FTD reloaded with no change window while WebVPN was enabled. Metabase ingress shows reset password 400 immediately followed by user current 200 from the same source. SharePoint received a Bearer JWT with alg none or a four byte signature after 12 Aug. vCenter Syslog service showed path traversal sequences followed by new cron entries or outbound SSH to non management IPs. Adobe Magento session cookie bound customer id changed mid session without intervening logout login. Salesforce or ServiceNow guest portals showed high volume unauthenticated enumeration since March 2025. Android device received inbound call then sideloaded non Play Store APK then Accessibility Service grant then NFC activity in the same session.

SIGMA SecurityPDF drop and sideload

title: Dream Job SecurityPDF or libmupdf sideload
id: 7c2e1b90-0813-2026-lazarus-pdf
status: experimental
logsource:
  product: windows
  category: process_creation
detection:
  sel_drop:
    ParentImage|endswith:
      - '\SecurityPDF.exe'
      - '\sumatrapdf.exe'
    Image|endswith: '\new.exe'
    Image|contains: '\Temp\'

SIGMA FudModule privilege hop


SIGMA Metabase reset password then session


SIGMA SharePoint alg none JWT


SIGMA Cisco ASA FTD DoS Pattern

title: Cisco ASA FTD Unplanned Reload Following SSL VPN Request Spike CVE-2026-20349
id: 8f2b1a10-cisco-asa-dos-2026
status: experimental
logsource:
  product: cisco
  service: asa
detection:
  selection_reload:
    event.action: ['reload','service-restart','process-crash']

SIGMA VMware vCenter Path Traversal Followed by Reverse SSH Persistence

title: VMware vCenter Syslog Path Traversal Followed by Reverse SSH Persistence CVE-2026-59310
id: 4c9d7e21-vcenter-pathtrav-2026
logsource:
  product: vmware
  service: vcenter
detection:
  selection_traversal:
    http.url.path|contains: ['../','%2e%2e%2f']

SIGMA Magento Adobe Commerce Cross Account Session Switch


SIGMA Android Sideload Accessibility Abuse NFC Correlation


YARA RelayShell consulted sources reproduced

rule lazarus_relayshell
{
  meta:
    author = "_CPResearch_

YARA SecurityPDF marker and FudModule strings


YARA reverse ssh Persistence Tool generic pattern unconfirmed sample hash


SIEM field logic vendor neutral

JOIN process_create p
  WITH image_load l ON p.process_guid = l.process_guid
  WITH network n ON p.process_guid = n.process_guid
WHERE (
      l.module_name == "libmupdf.dll"
      AND l.module_path NOT LIKE "%\\Program Files%"
    )
    OR (p.file_path LIKE "%\\Temp\\

D3FEND inferred controls not source mapped D3 SU Software Update D3 FH File Hashing D3 NTA Network Traffic Analysis D3 UA User Training on recruiter lures D3 IAA Identifier Activity Analysis on Graph tokens D3 EHB Endpoint Health Beacon for ETW minifilter disappearance D3 ITF Isolation so RA VPN is not the only path D3 AL Application Lockout block reset password.

No publisher in this window printed ATT and CK IDs for the Dream Job cluster. Each mapping below is inferred from consulted sources wording or source mapped where stated. Do not treat IDs as vendor mapped unless noted.

T1566.003 Spearphishing via Service T1566.002 Spearphishing Link consulted sources assess LinkedIn or messaging recruiter personas from prior Dream Job waves exact 2026 approach remains unclear. Behavioral basis fake Lockheed Martin Enveil jobs then a download.

T1204.002 User Execution Malicious File victim launches the signed viewer or SecurityPDF and opens the crafted PDF.

T1574.002 DLL Side Loading libmupdf.dll loaded by the legitimate viewer.

T1027 Obfuscated Files or Information encrypted zip XOR 0x39 PDF payload AES Graph files GOST CBC LPE channel.

T1620 Reflective Code Loading T1055 Process Injection MISTPEN reflective DLL load Troy loaded from new.exe FudModule injects MISTPEN into a SYSTEM process.

T1068 Exploitation for Privilege Escalation CVE-2026-68820 in afd.sys.

T1014 Rootkit FudModule 3.1 kernel module.

T1562.001 Impair Defenses Disable or Modify Tools T1562.006 Indicator Blocking callback minifilter ETW teardown Smart App Control disable generic security product suppressor.

T1112 Modify Registry VerifiedAndReputablePolicyState set to 0.

T1134 Access Token Manipulation privileged handle forgery described for FudModule v3 v3.1.

T1547 Boot or Logon Autostart persistence module installs the malware on disk and survives reboot exact sub technique insufficient data.

T1082 T1057 T1033 T1083 Discovery GetInfoPlugin PvPlugin Troy recon file enum.

T1113 Screen Capture OneScreenCapture64.dll.

T1102.002 Bidirectional Web Service MISTPEN on OneDrive via Graph API.

T1071.001 Web Protocols Troy HTTP RelayShell HTTP POST.

T1090.003 Multi hop Proxy RelayShell victim operator file channel plus backbone PID.

T1505.003 Web Shell RelayShell on Roundcube CMS.

T1190 Exploit Public Facing Application CVE-2025-49113 on Roundcube CVE-2026-20349 on ASA FTD CVE-2026-72898 on Metabase CVE-2026-55040 on SharePoint CVE-2026-59310 on vCenter CVE-2026-71362 on Adobe.

T1583.001 Acquire Infrastructure Domains T1608.006 SEO Poisoning envell.xyz enveil.online uxtramine.org ranking for Enveil SecurityPDF.

T1584.004 Compromise Infrastructure Server hijacked WordPress SharePoint Roundcube PrestaShop.

T1041 Exfiltration Over C2 Channel Troy archive exfil commands MISTPEN upload of recon strings.

T1499 Endpoint Denial of Service Cisco device reload. Closest Impact technique for availability only firewall crash. Source mapped T1498 Network Denial of Service for Cisco.

T1219 Remote Access Software inferred reverse ssh for VMware.

T1053.003 Scheduled Task Job Cron inferred for VMware.

T1078 Valid Accounts inferred Adobe session context switching.

T1213 Data from Information Repositories inferred City Forum.

T1656 Impersonation source mapped WindRelay SpyNote vishing pretext as bank staff.

T1417 Input Capture inferred mobile NFC EMV data captured live during a call.

Chapter 05 - Governance, Risk & Compliance

FCEB and anyone who pretends to follow BOD 22 01 BOD 26 04 CVE-2026-20349 and CVE-2026-72898 are due 14 Aug 2026. CVE-2026-68820 is due 25 Aug 2026. Required action language on NVD KEV tables is apply vendor mitigations follow BOD 26 04 risk based patching and CISA forensics triage and discontinue the product if you cannot mitigate. That is a compliance date not a threat date. Lazarus did not wait for 25 Aug. Cisco exploitation is already this month.

Boards in defense aerospace and aviation should ask three questions that have yes no answers Are August Windows updates on every endpoint that talks to program networks Did any staff receive recruiter PDFs from outside the ATS this quarter and did IR look Are Roundcube and other webmail appliances patched for CVE-2025-49113 and crawled for RelayShell

Cisco RA VPN is a business continuity issue. A reload is a workforce cut off not a confidentiality footnote. Schedule the hotfix as an emergency change not a monthly stack. US federal agencies face a hard CISA KEV deadline of 14 August 2026 one day after this window closes. Non federal orgs should treat KEV inclusion as a de facto industry SLA benchmark for regulated entities. Availability impact DoS on core network VPN infra creates business continuity risk independent of any confidentiality breach threshold.

Metabase is a data governance issue. Admin on the BI box is admin adjacent on every warehouse it can see. Rotate connectors even if the 400 200 pattern is absent absence of logs is not absence of access.

SharePoint July patch compliance is now an exploitation issue not a hygiene backlog. If the farm is still on a pre July build assume scanners have the Rapid7 PoC.

VMware vCenter RCE Notification Threshold Uncertainty Since CVE-2026-59310 is not yet CISA KEV listed organizations may under prioritize it despite CVSS 9.8 and reported active exploitation. Recommend treating it as KEV equivalent internally given the confirmed patch to exploit gap. If PII PHI resides on systems managed via a compromised vCenter breach notification thresholds GDPR 72 hour rule US state laws may be triggered by host compromise even absent confirmed data exfiltration.

Adobe Commerce PCI DSS and Customer Data Exposure Risk Confirmed cross account session exploitation on a payment handling e commerce platform raises PCI DSS scope questions regardless of Adobe no confirmed exploitation stance Sansec blocked attempt telemetry shows active targeting. Merchants should document patch timing and WAF deployment as compensating control evidence.

City Forum Third Party Guest Access Governance Gap This campaign is a GRC blind spot guest anonymous portal misconfiguration is a customer owned control not a vendor patch so standard vulnerability management will not catch it. Add guest access configuration review to periodic access control audits distinct from patch management.

WindRelay SpyNote Consumer Fraud Liability and Regional Regulatory Exposure Financial institutions in Czechia Slovakia and Slovenia face potential scrutiny under EU PSD2 strong customer authentication requirements if contactless fraud losses are attributed to inadequate anti fraud controls. Consumer fraud awareness communication is a mitigating factor to document.

Trezor ShipMonk Supply Chain Fourth Party Risk and Cross Border Notification A fourth party risk event Trezor ShipMonk Metabase affecting customers across 7 jurisdictions US UK Sweden Colombia Brazil Italy Portugal each with distinct breach notification regimes. Trezor statement that devices keys are unaffected narrows scope to contact PII but the multi jurisdiction footprint still requires coordinated notification tracking. Reassess vendor risk questionnaires to explicitly cover Metabase BI tool exposure.

Do not write a single nation state cyber crisis brief that glues Cisco Metabase SharePoint VMware Adobe City Forum WindRelay and Trezor to Lazarus. The evidence does not support it. Write separate risk statements. Brief the defense sector one to the CISO and the CHRO together.

Chapter 06 - Adversary Emulation

Scope these as purple team vignettes. Do not replay the afd.sys exploit Cisco crash packet Metabase SQLi or VMware path traversal against production. No exploit payloads.

Vignette 1 Dream Job delivery without the zero day Pretext a defense adjacent user with a fake requisition. Deliver a zip containing a signed viewer and a benign DLL with the name libmupdf.dll that only beacons to a lab Graph app. Success EDR catches user writable sideload and Graph from a PDF process. Fail it waits for SYSTEM.

Vignette 2 SecurityPDF marker Build a PDF that contains only the Sumatra marker string and a non malicious XOR 0x39 blob that writes a lab beacon to TEMP new.exe. Success content inspection or ASR blocks the drop. Fail the viewer is treated as productivity software.

Vignette 3 FudModule hop without the UAF From a standard user session attempt to spawn SYSTEM msiexec via a documented authorized admin tool in the lab then set a dummy CI policy value. Success SOC alerts on services.exe msiexec SYSTEM outside a patch window and on SAC policy flips. Do not call undocumented NtSetSystemInformation options on production.

Vignette 4 RelayShell Stand up a disposable PHP app that implements send receive via id1.log id2.log. Point a lab implant at it. Success web shell hunting finds the pair of session files and the dual password POST. Bonus detect ExpressVPN sourced admin POSTs to Roundcube paths.

Vignette 5 SharePoint JWT control check On a July patched lab farm submit a Bearer token with alg none and a dummy signature against vti bin. Success 401 and an IIS analytic. Fail any 200 that looks like a user context. Stop. Do not enumerate SIDs.

Vignette 6 Metabase and Cisco change control Tabletop only. Walk NOC through an unscheduled ASA reload with WebVPN on. Walk the data team through the reset password 400 user current 200 pair. Score whether the pageable owner exists at 02 00.

Vignette 7 VMware vCenter Emulate T1190 with crafted traversal requests against a lab vCenter Syslog port 514 and confirm detection of the traversal pattern independent of successful exploitation. Emulate T1053.003 T1219 by manually planting a cron entry and an outbound SSH session since the actual reverse ssh sample is not publicly available for safe emulation.

Vignette 8 Adobe Commerce In a staging Magento Adobe Commerce instance simulate a session where the bound customer id changes without a logout event and confirm the session switch rule fires excluding legitimate CS impersonation tooling via a distinct event type.

Vignette 9 City Forum Run an authenticated internal review of your own Salesforce Experience Cloud guest profile and ServiceNow Service Portal ACLs against the object field categories reported exploited customer records case data.

Vignette 10 WindRelay SpyNote Run a tabletop exercise simulating the vishing to sideload chain confirm MDM policy blocks non Play Store APK installs and that Accessibility Service grants on managed devices trigger alerts. Validate that fraud awareness messaging covers the tap your card against your phone during a call pretext.

Vignette 11 Trezor ShipMonk Review third party logistics BI vendor contracts for Metabase or similar self hosted analytics exposure request confirmation of patch status against the 8 August 2026 Metabase zero day disclosure as part of ongoing vendor risk management.

Atomic tests to skip live CVE-2026-68820 live CVE-2026-20349 live CVE-2026-72898 Rapid7 PoC against a production farm live CVE-2026-59310 live CVE-2026-71362.

Intelligence Confidence68%


Component

Score

Rationale

Lazarus Dream Job cluster

76

Consulted sources primary on campaign CISA KEV plus Microsoft and Cisco exploitation statements remove doubt NVD corroborates CWE KEV dates Metabase CVSS 4.0 10.0 two independent outlets carried Lazarus and Cisco on 12 Aug THN carried SharePoint on 13 Aug Deductions Microsoft MSRC HTML and Cisco PSIRT HTML did not render so some vectors taken from secondary quotes Microsoft not observed naming Lazarus Cisco Metabase SharePoint actors unknown KEVIntel telemetry single path no independent IOC enrichment Check Point blog timestamp just outside window start but used because in window reporting depends on it Single source claims dropped or marked unconfirmed

Cisco CVE-2026-20349

85

CISA KEV T1 confirmed

VMware CVE-2026-59310

52

Critical severity IR firm reported exploitation single primary reporter relayed via secondary no CISA confirmation

Adobe CVE-2026-71362

48

Vendor denies confirmed exploitation single vendor research source but two outlets corroborate

City Forum

46

Corroborated across three outlets but zero T1 confirmation no actor CVE

WindRelay SpyNote

44

Single primary source with secondary syndication

Trezor ShipMonk

68

Self disclosed high confidence on breach scope lower confidence on root cause chain Metabase link sourced from customer email not official advisory

Composite

68

Mixed confidence day one government confirmed KEV item pulls average up while remaining clusters rely on single vendor or IR firm primary reporting without independent T1 corroboration inside window No IOC values available for independent verification on non Lazarus clusters which caps those items Attribution absent or unconfirmed across majority of clusters