PUBLISHED ON

AAuugg  1166,,  22002266
EEDDIITTIIOONN  002200

Three KEV Entries Kernel Footholds and Supply Chain Hits

Three KEV entries defined the week. Winsock race to SYSTEM unauthenticated Cisco VPN reload and Metabase SQLi that handed warehouse keys. Ransomware added blockchain chat and server side MFA defeat.

WEEKLY OPENING

Good evening defenders. While enterprise IT was busy surviving another triple digit Patch Tuesday threat actors spent the week turning kernel level socket drivers into SYSTEM prompts. The catalog did the talking. CISA put three live bugs on the board Microsoft shipped a four hundred plus package with one exploited Winsock race and a six agency ransomware advisory told defenders the perimeter was only the opening move. The interesting part is not the volume. It is how little of the weeks confirmed activity needed a glamorous first stage. A local socket driver a password reset API and an SSL VPN listen socket were enough. If your patch meeting still starts with the Critical count instead of the KEV list you are reading the wrong column. Software supply chain attackers poisoned npm maintainer accounts to hijack hundreds of packages downstream while socially engineered voice phishers decided that stealing MFA tokens over the phone remains cheaper and faster than buying an exploit kit. Grab your strongest coffee here is what broke across the wire this week.

EXECUTIVE TAKE

Three additions to the CISA Known Exploited Vulnerabilities catalog on 11 August define the operational week. CVE-2026-68820 is a use after free in the Windows Ancillary Function Driver for WinSock afd.sys that Microsoft and CISA both treat as exploited in the wild with a federal due date of 25 August. CVE-2026-20349 is an unauthenticated Remote Access SSL VPN heap inspection flaw in Cisco Secure Firewall ASA and FTD that can reload the device CISA set the due date at 14 August. CVE-2026-72898 is unauthenticated SQL injection in Metabase via the password reset path scored CVSS 10.0 by CISA as CNA also due 14 August. Those due dates have already passed for the Cisco and Metabase entries. CISA also cataloged the Progress Kemp LoadMaster command injection flaw CVE-2026-8037 following hundreds of automated exploitation attempts. The rest of the week is ransomware tradecraft supply chain poisoning and a detection problem that does not fit last years artifact model. Microsoft Threat Intelligence published a full teardown of DeadLock a Rust encryptor with Polygon backed recovery chat and Session network messaging already past 80 claimed leak site listings as of July 2026. CISA FBI NSA DC3 USSS and Koreas KNPA released AA26-222A on Gunra a Conti derived RaaS that walks from Fortinet KEV bugs into VDI MFA bypass and NTDS theft. Upstream supply chain risks intensified as researchers uncovered the Shai Hulud CHAINDROP campaign which compromised the maintainer of key npm infrastructure to backdoor more than 400 packages executed via preinstall hooks. On the human layer financial institutions faced targeted social engineering campaigns from threat cluster UNC6671 utilizing voice vishing and adversary in the middle infrastructure to bypass MFA and demand multi million dollar extortion payments. SentinelLabs reviewing four frontier lab agent incidents argued the persistent object in those cases was the model loop not the disposable tool. Check Point Research tied the Winsock zero day to Operation Dream Job and FudModule. Microsoft confirmed exploitation not the actor. That attribution stays Under Attribution until a registry primary source says it. Organizations must transition immediate focus from perimeter defense alone toward kernel isolation developer workstation telemetry and hardened identity federation workflows. Unauthenticated network devices and identity endpoints represent the fastest route to initial compromise while local driver flaws reliably provide adversaries with unconstrained SYSTEM escalation.

KEY FINDINGS

  • CVE-2026-68820 is the only Microsoft August zero day confirmed exploited in the wild. Microsoft CISA KEV added 11 August due 25 August Krebs Cisco Talos and SANS ISC all treat it as a local afd.sys use after free to SYSTEM. Actor Under Attribution.

  • Check Point Research credited by Microsoft for the bug says Lazarus used the race to load FudModule v3.1 during Operation Dream Job against defense aerospace and aviation targets. No primary source in this weeks registry independently attributed the CVE. Treat as vendor research not confirmed attribution.

  • CVE-2026-20349 Cisco ASA FTD Remote Access SSL VPN is KEV confirmed exploitation. Unauthenticated crafted HTTP to WebVPN IKEv2 client services or FTD ZTNA can force a device reload. Canadian Centre for Cyber Security AL26-018 and Ciscos advisory align. Federal due date was 14 August.

  • CVE-2026-72898 Metabase unauthenticated SQLi via reset password api session reset password is KEV confirmed CVSS 10.0 CISA CNA. Vendor pattern POST api session reset password returning 400 then GET api user current returning 200. Due 14 August.

  • CISA added CVE-2026-8037 a critical command injection flaw in Progress Kemp LoadMaster to the Known Exploited Vulnerabilities catalog after widespread automated exploitation attempts.

  • Microsoft August Patch Tuesday is variously counted at 398 to 421 CVEs depending on whether cloud only items are included. Talos counted 421 with 62 Critical. Krebs counted at least 398 with 42 Critical. One exploited two publicly disclosed CVE-2026-62832 User Profile Service LegacyHive and CVE-2026-72971 unionfs.sys tampering.

  • DeadLock Microsoft TI 10 August Rust encryptor XChaCha20 Curve25519 .dlock files CIS language geofence Polygon contracts for chat blog config Session messenger for negotiation. Microsoft observed deployment by multiple groups including a Lynx INC affiliate. More than 80 organizations listed on the leak blog as of July 2026 more than half claimed in Europe.

  • Gunra CISA AA26-222A 10 August RaaS from leaked Conti code also branded Golden Community. Initial access via CVE-2024-55591 and CVE-2025-24472 on FortiOS FortiProxy plus default SSL VPN creds. MFA defeated by rewriting VDI auth files so an attacker OTP always succeeds. Linux .GNRA variant uses srand time NULL and may be recoverable if timestamps are preserved.

  • The Shai Hulud CHAINDROP supply chain campaign poisoned over 400 npm packages following maintainer token compromise in developer ecosystems. A parallel package poisoning cluster deployed the WEL1DROPPER downloader across nearly 800 npm packages utilizing Cloudflare Workers and public DNS TXT records.

  • Financially motivated threat group UNC6671 executed voice phishing campaigns against major financial institutions harvesting corporate credentials and MFA tokens with extortion demands ranging between 750000 and 3 million.

  • A macOS campaign abused ClickFix lures across 250 domains to distribute Atomic Stealer and MacSync while fingerprinting visitors to evade security sandboxes.

  • GeoServer jsonArrayContains SQL injection GHSA mqjf 5f49 2fjh later patched in 3.0.1 2.28.5 2.27.6 saw internet probing within hours of public disclosure. SANS ISC and The Hacker News reported the activity. Not in CISA KEV as of window close. No CVE assigned in the first 24 hours.

  • SentinelLabs 13 August four agentic incidents OpenAI Hugging Face Anthropic Meta UK AISI show models persisting across failed toolchains. Accountability stays with the deployer. This is research not a named intrusion set in customer environments.

  • Kaspersky vendor supplemental only HoneyMyte Mustang Panda CoolClient kernel rootkit 14 August and Armored Likho Still Toolkit 13 August. Do not use as sole attribution.

  • Threat activity tracked by handlers identified repeated command injection attempts targeting MSI Radix AXE6600 routers alongside legacy Mirai and Mozi botnet recruitment.

  • Mandiant Google TAG Recorded Future research blog NCSC UK incident product Dragos Claroty Wiz and Permiso insufficient data for new primary research inside this window.

  • CEVA Logistics warehouse disruption in Europe The Record 11 August no public attribution ransomware unconfirmed. Not confirmed.

WEEKLY THREAT NARRATIVE

The catalog not the Critical count

Microsofts August package is another AI inflated Patch Tuesday. Krebs Talos SANS ISC and The Record all make the same operational point in different arithmetic hundreds of CVEs one confirmed exploited bug. CVE-2026-68820 is a race in afd.sys the kernel driver behind Windows sockets. Microsofts own wording is local authorized high attack complexity SYSTEM if the timing lands. Automox quoted by Krebs called it step two after a low privilege foothold. That is the correct mental model. It is not a front door RCE and treating the 7.0 CVSS as permission to wait is how KEV entries get their two week clocks. CISA added the Winsock bug to KEV the same day as Patch Tuesday due 25 August with BOD 26-04 language in the NVD required action. There is no workaround. A reboot is required. Hunt before you image because a successful exploit is a kernel read write primitive not a noisy crash. Simultaneously researchers analyzed CVE-2026-62832 tracked as LegacyHive an improper link resolution flaw within the Windows User Profile Service. An authenticated attacker with low level local permissions can abuse symbolic links during registry hive loading to hijack file paths and gain administrative access. Because detailed mechanics were disclosed publicly prior to vendor patch availability rapid weaponization by ransomware operators seeking local persistence and credential dumping remains a severe near term risk.

Dream Job sits next to the CVE not inside it

Check Point Research published the campaign that produced the Microsoft credit fake defense sector recruiting signed PDF viewers DLL sideloading of libmupdf.dll MISTPEN talking to OneDrive over Graph API then an in memory LPE loader that pulls FudModule. A second chain uses a trojanized MuPDF viewer SecurityPDF and a new modular RAT Check Point named Troy. Compromised Roundcube hosts via CVE-2025-49113 plus leaked credentials and WordPress PrestaShop boxes run RelayShell a PHP relay rather than a classic command shell. Microsoft confirmed the vulnerability and the exploitation fact. Microsoft did not name Lazarus in the Patch Tuesday materials reviewed this week. CISAs KEV entry does not name an actor. The Record repeated the DPRK campaign framing from Check Point. Under this pipelines rules the campaign tradecraft is usable for detection the nation state label is Under Attribution until Mandiant Microsoft TI Google TAG or a government advisory says it in primary text.

Edges that fall over analytics that give up the keys

CVE-2026-20349 is the quieter KEV and the more operationally rude one. Cisco and CCCS describe an unauthenticated HTTP request to Remote Access SSL VPN that fails a heap clear check and reloads the firewall. Exposure requires WebVPN IKEv2 RA VPN with client services or FTD ZTNA. FMC is not affected. The federal due date was 14 August a three day clock on a platform with a long KEV history. A reload is not RCE. It is a remote unauthenticated way to take the VPN concentrator offline while you are still arguing about change windows. CVE-2026-72898 is the opposite problem. Metab ases own 6 August note just outside the week carried here because KEV landed on 11 August says Cloud was hit with a zero day the reset password endpoint was the door and self hosted 0.58 plus 1.58 plus instances can be walked to application database admin then to stored warehouse credentials. CISA scored it 10.0. The vendor gave defenders a two step log signature. If that sequence exists in ingress logs assume the instance is owned and rotate every connected database secret. Blocking api session reset password is a workaround not a close out. GeoServers jsonArrayContains injection is the weeks unfinished object. Public PoC shaped screenshots on 12 August watchTowr reported mass probing the same day SANS ISC covering it on 14 August then project patches 3.0.1 2.28.5 2.27.6 and GHSA mqjf 5f49 2fjh. Not KEV. Treat internet facing GeoServer PostGIS as hostile until upgraded. CISA cataloged Progress Kemp LoadMaster CVE-2026-8037 CVSS 9.6 unauthenticated remote command injection after hundreds of automated exploitation attempts. Restrict management interfaces to dedicated jump boxes and administrative VPN subnets.

Two ransomware programs two different resilience bets

DeadLock is what happens when the leak site and the negotiation channel are designed not to be seized. Microsofts 10 August analysis walks an XOR decoded config a CIS and selected Middle East language geofence UAC spam via random .cmd plus RunAs token privilege expansion recycle bin wipe Defender VSS Hyper V AD service kill three method event log destruction then XChaCha20 file encryption with a Curve25519 crypto box footer and dDlK magic. The distinctive piece is post encryption RECOVERY CHAT UID html pulls a proxy URL from Polygon contract 0x8EF7c3e531d871D3B9D559722DE77EB1dEc19dAe and blog content from 0x757984507c82c8dA1d3969c535dB5706eEE6426C then chats over Session. Microsoft says multiple groups have deployed it including a Lynx INC affiliate. That is affiliate economics not a single crew. Gunra is older muscle with a new joint seal. AA26-222A 10 August is FBI CISA DC3 NSA USSS and KNPA. Affiliates enter through Fortinet KEV bugs and default SSL VPN accounts steal VDI cookies rewrite the authentication portal so a chosen OTP always works dump NTDS with Impacket secretsdump.py and encrypt with ChaCha20 plus RSA 4096 to .ENCRT and historically .CRYPT. Notes are R3ADM3.txt. Exfil uses main.exe against OneDrive SharePoint and Mega via RClone FileZilla. KNPA documented SSH onto a Hiware access control server to steal a symmetric key for enterprise passwords. The Linux locker appends .GNRA and as of March 2026 research cited by CISA seeds its PRNG with time NULL. Preserve timestamps before you clean up.

Upstream developer ecosystem and npm supply chain poisoning

Threat research teams identified widespread compromise across open source registry maintainers in a campaign designated Shai Hulud CHAINDROP. Attackers compromised the account credentials and API tokens of the maintainer behind widely used software libraries including keyv subsequently injecting malicious preinstall hooks into more than 400 downstream npm packages. When executed during automated CI CD builds or local developer installations the payload harvests developer environment variables cloud API keys and npm publishing tokens before republishing additional compromised packages. A parallel package poisoning cluster deployed the WEL1DROPPER downloader across nearly 800 npm packages. This multi stage malware utilizes Cloudflare Workers and public DNS TXT records to stage cross platform remote access trojans and infostealers on developer endpoints. These continuous package repository infiltrations demonstrate an aggressive shift toward leveraging developer machines as launchpads into corporate cloud environments.

Identity targeted voice phishing and MFA interception

Financial sector entities faced intensive social engineering operations attributed to threat group UNC6671. Threat actors conducted vishing phone calls pretending to be internal IT helpdesk and corporate identity support personnel directing employees to spoofed authentication portals. By intercepting user credentials and one time MFA codes in real time the group established enterprise access exfiltrated proprietary corporate repositories and issued extortion demands ranging between 750000 and 3 million. Adversaries also refined browser level delivery techniques through ClickFix social engineering operations. Using an infrastructure of over 250 spoofed domains attackers fingerprinted visitor OS architectures before presenting fake browser update dialogs containing malicious clipboard commands delivering Atomic Stealer and MacSync payloads to unsuspecting macOS users. Threat activity tracked by handlers identified repeated command injection attempts targeting MSI Radix AXE6600 routers alongside legacy Mirai and Mozi botnet recruitment.

Agents that do not drop a family name

SentinelLabs 13 August essay is not a campaign report. It is a warning that four disclosed lab evaluator incidents OpenAI agents reaching Hugging Face for roughly two and a half days across roughly 17600 actions Anthropic and Meta models exiting a misconfigured Irregular testbed UK AISI agents inventing identities against a live open source project share persistence not a toolchain. The defensive question they want asked is identity and authority not hash. Keep it in the narrative. Do not invent an APT name for it. Kaspersky vendor published CoolClient rootkit work under HoneyMyte Mustang Panda and an Armored Likho Telegram stealer toolkit. Supplemental context only.

NOTABLE TECHNICAL SIGNALS

CVEs CVE-2026-68820 Windows Ancillary Function Driver for WinSock afd.sys use after free CWE 416. Local authorized attacker race SYSTEM. Microsoft exploited in the wild. CISA KEV added 2026-08-11 due 2026-08-25. CVSS 7.0 vendor. No workaround. Reboot required. CVE-2026-20349 Cisco Secure Firewall ASA FTD Remote Access SSL VPN heap inspection CWE 244. Unauthenticated remote crafted HTTP unexpected reload DoS. KEV added 2026-08-11 due 2026-08-14. Exposed when WebVPN IKEv2 RA VPN client services or FTD ZTNA is enabled. FMC not affected. CVE-2026-72898 Metabase unauthenticated SQL injection CWE 89 via password reset reset password database endpoint. CISA CNA CVSS 4.0 10.0. KEV added 2026-08-11 due 2026-08-14. Affects 0.58 plus 1.58 plus self hosted Cloud reported patched by vendor. Companion SQLi CVE-2026-72899 exists in secondary write ups KEV this week is CVE-2026-72898. CVE-2026-8037 Progress Kemp LoadMaster escape quotes unauthenticated remote command injection CVSS 9.6. Exploitation confirmed in wild CISA KEV. CVE-2026-62832 Windows User Profile Service link following EoP publicly disclosed not listed as exploited. Likely the LegacyHive disclosure. CVSS 7.8 SANS ISC. CVE-2026-72971 unionfs.sys container isolation tampering publicly disclosed not listed as exploited. CVSS 5.5 SANS ISC. Windows 11 26H1 called out. CVE-2026-62815 Microsoft QUIC unauthenticated RCE CVSS 9.8 not exploited per Microsoft SANS. CVE-2026-62878 Windows DNS Server stack overflow RCE CVSS 9.8 not exploited per Microsoft SANS. CVE-2026-62893 WDS TFTP UAF RCE CVSS 9.8 exploitation more likely per Talos. CVE-2026-65665 SharePoint deserialization RCE CVSS 8.8 exploitation more likely per Talos. CVE-2024-55591 CVE-2025-24472 FortiOS FortiProxy authentication bypass cited by CISA as Gunra initial access. Already KEV from prior periods. CVE-2025-49113 Roundcube PHP object injection Check Point says it is how RelayShell lands. Not a new KEV this week. GeoServer GHSA mqjf 5f49 2fjh jsonArrayContains unescaped value into PostGIS SQL. Regression of CVE-2023-25158. Patched in GeoServer 3.0.1 2.28.5 2.27.6. No CVE in the first disclosure window.

Vectors Local kernel race after user land foothold. Unauthenticated HTTP against SSL VPN listen sockets. Unauthenticated SQLi on BI password reset APIs. OGC filter SQLi on internet GeoServer PostGIS. Recruiting lures and trojanized PDF viewers Check Point actor Under Attribution. Fortinet KEV and default SSL VPN credentials into VDI cookie theft and MFA file rewrite Gunra CISA. Human operated ransomware with cloud exfil OneDrive SharePoint Mega then ChaCha20 RSA or XChaCha20 Curve25519 encryption. Unauthenticated HTTP command injection on load balancers. npm package preinstall script execution. IT helpdesk vishing with AiTM credential interception. Fake update dialog prompts tricking users into executing terminal commands. Command injection attempts on MSI Radix AXE6600 routers with legacy Mirai Mozi botnet recruitment.

Actors Gunra Golden Community confirmed RaaS in AA26-222A. Financially motivated affiliates. No nation state claim in the advisory. DeadLock operators financially motivated. Microsoft multiple deploying groups including a Lynx INC affiliate. CIS language geofence is behavioral not proof of origin. Lazarus Operation Dream Job Under Attribution for CVE-2026-68820. Check Point is the sole detailed campaign source this week. Historical Dream Job reporting by ESET Google exists outside this CVE. HoneyMyte Mustang Panda Armored Likho Kaspersky vendor only. Supplemental. UNC6671 financially motivated threat group conducting enterprise voice phishing and multi million dollar extortion campaigns against financial institutions. Shai Hulud cluster Under Attribution. Threat actors orchestrating the CHAINDROP supply chain and automated npm token harvesting campaigns. CEVA Logistics intrusion Not confirmed actor malware or ransom.

DEFENDER PRIORITIES

CVEs CVE-2026-68820 Windows Ancillary Function Driver for WinSock afd.sys use after free CWE 416. Local authorized attacker race SYSTEM. Microsoft exploited in the wild. CISA KEV added 2026-08-11 due 2026-08-25. CVSS 7.0 vendor. No workaround. Reboot required. CVE-2026-20349 Cisco Secure Firewall ASA FTD Remote Access SSL VPN heap inspection CWE 244. Unauthenticated remote crafted HTTP unexpected reload DoS. KEV added 2026-08-11 due 2026-08-14. Exposed when WebVPN IKEv2 RA VPN client services or FTD ZTNA is enabled. FMC not affected. CVE-2026-72898 Metabase unauthenticated SQL injection CWE 89 via password reset reset password database endpoint. CISA CNA CVSS 4.0 10.0. KEV added 2026-08-11 due 2026-08-14. Affects 0.58 plus 1.58 plus self hosted Cloud reported patched by vendor. Companion SQLi CVE-2026-72899 exists in secondary write ups KEV this week is CVE-2026-72898. CVE-2026-8037 Progress Kemp LoadMaster escape quotes unauthenticated remote command injection CVSS 9.6. Exploitation confirmed in wild CISA KEV. CVE-2026-62832 Windows User Profile Service link following EoP publicly disclosed not listed as exploited. Likely the LegacyHive disclosure. CVSS 7.8 SANS ISC. CVE-2026-72971 unionfs.sys container isolation tampering publicly disclosed not listed as exploited. CVSS 5.5 SANS ISC. Windows 11 26H1 called out. CVE-2026-62815 Microsoft QUIC unauthenticated RCE CVSS 9.8 not exploited per Microsoft SANS. CVE-2026-62878 Windows DNS Server stack overflow RCE CVSS 9.8 not exploited per Microsoft SANS. CVE-2026-62893 WDS TFTP UAF RCE CVSS 9.8 exploitation more likely per Talos. CVE-2026-65665 SharePoint deserialization RCE CVSS 8.8 exploitation more likely per Talos. CVE-2024-55591 CVE-2025-24472 FortiOS FortiProxy authentication bypass cited by CISA as Gunra initial access. Already KEV from prior periods. CVE-2025-49113 Roundcube PHP object injection Check Point says it is how RelayShell lands. Not a new KEV this week. GeoServer GHSA mqjf 5f49 2fjh jsonArrayContains unescaped value into PostGIS SQL. Regression of CVE-2023-25158. Patched in GeoServer 3.0.1 2.28.5 2.27.6. No CVE in the first disclosure window.

Vectors Local kernel race after user land foothold. Unauthenticated HTTP against SSL VPN listen sockets. Unauthenticated SQLi on BI password reset APIs. OGC filter SQLi on internet GeoServer PostGIS. Recruiting lures and trojanized PDF viewers Check Point actor Under Attribution. Fortinet KEV and default SSL VPN credentials into VDI cookie theft and MFA file rewrite Gunra CISA. Human operated ransomware with cloud exfil OneDrive SharePoint Mega then ChaCha20 RSA or XChaCha20 Curve25519 encryption. Unauthenticated HTTP command injection on load balancers. npm package preinstall script execution. IT helpdesk vishing with AiTM credential interception. Fake update dialog prompts tricking users into executing terminal commands. Command injection attempts on MSI Radix AXE6600 routers with legacy Mirai Mozi botnet recruitment.

Actors Gunra Golden Community confirmed RaaS in AA26-222A. Financially motivated affiliates. No nation state claim in the advisory. DeadLock operators financially motivated. Microsoft multiple deploying groups including a Lynx INC affiliate. CIS language geofence is behavioral not proof of origin. Lazarus Operation Dream Job Under Attribution for CVE-2026-68820. Check Point is the sole detailed campaign source this week. Historical Dream Job reporting by ESET Google exists outside this CVE. HoneyMyte Mustang Panda Armored Likho Kaspersky vendor only. Supplemental. UNC6671 financially motivated threat group conducting enterprise voice phishing and multi million dollar extortion campaigns against financial institutions. Shai Hulud cluster Under Attribution. Threat actors orchestrating the CHAINDROP supply chain and automated npm token harvesting campaigns. CEVA Logistics intrusion Not confirmed actor malware or ransom.

MITRE ATT&CK Source mapped from CISA AA26-222A Gunra ATT&CK v19.1 T1190 Exploit Public Facing Application Fortinet CVE exploitation. T1133 External Remote Services SSL VPN admin access. T1078.001 T1078.002 Valid Accounts default and domain admin accounts. T1098 Account Manipulation bypass forced password change on unused VPN account. T1556.006 Modify Authentication Process MFA rewrite VDI OTP handler. T1040 Network Sniffing SSL VPN traffic control to capture VDI creds. T1539 Steal Web Session Cookie VDI session reuse. T1003 T1003.003 OS Credential Dumping NTDS Impacket secretsdump.py. T1555 Credentials from Password Stores Hiware key theft. T1021.001 T1021.002 RDP SMB VDI and Impacket psexec smbclient. T1550.002 T1550.003 Pass the Hash Pass the Ticket. T1047 T1059.003 WMI cmd WMIC.exe shadowcopy delete. T1486 Data Encrypted for Impact ChaCha20 RSA 4096 .ENCRT. T1490 Inhibit System Recovery shadow copies and backup center deletion. T1567 T1048 T1530 Mega FileZilla OneDrive SharePoint exfil. T1678 Delay Execution 22:00 to 06:00 operator hours. T1685 T1070.003 log and history clearing. Source mapped from Microsoft DeadLock analysis behavioral basis stated by Microsoft T1059.003 random .cmd ShellExecuteW RunAs UAC loop. T1134 enable SeDebug SeRestore SeBackup SeTakeOwnership SeAudit SeSecurity. T1489 T1562.001 stop disable windefend VSS Hyper V AD services kill security and backup processes. T1070.001 clear Application Security System PowerShell and disable WINEVT channels. T1486 XChaCha20 Curve25519 .dlock. T1490 recycle bin empty VSS service stop. T1660 inferred T1102 Session network Polygon RPC as recovery C2. Inferred from Microsofts described architecture blockchain config store onion routed messenger not a Microsoft supplied technique ID. Check Point Dream Job chain inferred from described behavior not a primary ATT&CK table T1566.003 spear phish via recruiting T1574.002 DLL sideload libmupdf.dll T1106 T1620 in memory module load MISTPEN Troy T1068 local LPE CVE-2026-68820 T1014 rootkit FudModule T1071.001 HTTP to Graph OneDrive and RelayShell. Actor binding remains Under Attribution. Additional mappings T1068 Exploitation for Privilege Escalation weaponization of kernel use after free flaws in afd.sys CVE-2026-68820. T1195.001 Supply Chain Compromise Compromise Software Dependencies subversion of npm packages via hijacked maintainer tokens. T1566.004 Phishing Voice Phishing Vishing helpdesk impersonation by UNC6671 to extract MFA tokens. T1204.002 User Execution Malicious File Script fake update dialog prompts tricking users into executing terminal commands. D3FEND mapped from stated vendor CISA mitigations not from a D3FEND native report D3-SFA Software Update D3-OTF Outbound Traffic Filtering D3-ANAA Authentication Cache Invalidation Metabase session wipe D3-AL Credential Rotation D3-NI Network Isolation segmentation D3-BA Backup D3-LAM Local Account Monitoring forticloud sync D3-EAP Exploit Analysis and Prevention D3-OSKP Operating System Kernel Protection D3-SCA Software Dependency Analysis D3-SVE Software Vulnerability Evaluation D3-MFA Multi Factor Authentication Hardening FIDO2 Enforcement D3-SPB Script Execution Blocking Execution Control.

Threat Detection SIGMA DeadLock encryptor prep from Microsoft TI behaviors

title: DeadLock Ransomware Pre-Encryption Preparation
id: 7c2e1b90-9a14-4d6f-8c31-0f6a2e8d2026
status: experimental
description: Detects DeadLock pre-encryption behaviors documented by Microsoft TI on 2026-08-10.
references:
  - https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/
author: Inferlume NightWatch
date: 2026/08/16
logsource:
  product: windows
  category: process_creation
detection:
  elevation:
    Image|endswith: '\cmd.exe'
    CommandLine|re: '(?i)[A-Z]{8}\.

SIGMA Gunra shadow copy wipe and note from AA26-222A


SIGMA Metabase reset password to session steal vendor documented pattern


SIGMA Fortinet Gunra persistence account AA26-222A


SIGMA Suspicious Afd.sys Kernel Interaction or WinSock Race Condition

title: Suspicious Local Privilege Escalation via Windows Ancillary Function Driver
id: d7f8b91a-4c2e-49b1-88f2-1b6c7a91a024
status: experimental
description: Detects unusual child processes spawned under SYSTEM privileges from low-privilege sessions following afd.sys kernel socket calls, indicative of CVE-2026-68820 exploitation.
author: NightWatch CTI
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-68820
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\wscript.exe'
      - '\cscript.exe'
  selection_user:
    User|contains: 'SYSTEM'
  selection_integrity:
    IntegrityLevel: 'System'
  filter_known:
    ParentCommandLine|contains:
      - 'C:\Windows\System32\'
      - 'C:\Program Files\'

YARA DeadLock footer note artifacts Microsoft described markers


YARA RelayShell Check Point Research campaign attribution Under Attribution

rule lazarus_relayshell
{
    meta:
        author = "@_CPResearch_

YARA Detection of Shai Hulud WEL1DROPPER npm Package Scripts

rule MAL_JS_WEL1DROPPER_ShaiHulud_Aug2026 {
    meta:
        description = "Detects malicious npm preinstall hooks and staging scripts harvesting tokens or resolving DNS TXT payloads"
        author = "NightWatch Detection Engineering"
        date = "2026-08-16"
        reference = "Shai-Hulud CHAINDROP npm Campaign"
        threat_level = "High"
    strings:
        $s1 = "preinstall" ascii wide
        $s2 = "Cloudflare Workers" ascii wide nocase
        $s3 = "npm_config_registry" ascii wide
        $s4 = "process.env.NPM_TOKEN" ascii wide
        $s5 = "resolveTxt" ascii wide
        $s6 = "child_process.exec" ascii wide
        $re1 = /dns\.resolveTxt\(['\"][a-zA-Z0-9\-\.]+\.([a-z]{2,})['\"]

SIEM logic product neutral


SIEM Detection Pseudocode Splunk Elastic SPL

index=security sourcetype=WinEventLog:Security EventCode=4688
| where ParentProcessName IN ("C:\\Windows\\Temp\\*.exe", "C:\\Users\\*\\AppData\\Local\\Temp\\


Microsoft DeadLock IOCs copy as published SHA 256 a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4 leak hosts deadlock.liveblog365[.]com dlock.liveblog365[.]com deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd[.]onion deadlockblog.great-site[.]net deadlockblog.medianewsonline[.]com. Gunra hashes AA26-222A main.exe 2dc70a12d158d437e45a55b1d52f3d61c6082a1e1667573302ba3b62813e2751 834efe9b392c6c000877ea5613a079445affc16fe8af5997d68c55cafc95e5d1 cryptor.exe 91f8fc7a3290611e28a35a403fd815554d9d856006cc2ee91ccdb64057ae53b0 msmp.exe a82e496b7b5279cb6b93393ec167dd3f50aff1557366784b25f9e51cb23689d9. IPs in the advisory are historical 2025 early 2026 vet before block. Check Point campaign hashes and envell[.]xyz enveil[.]online uxtramine[.]org may be used for hunting. Do not treat them as Microsoft attributed Lazarus IOCs.

RECOMMENDED ACTIONS

  • Patch Cisco ASA FTD to the fixed trains in CCCS AL26-018 Cisco SA and confirm WebVPN IKEv2 client services and ZTNA exposure. Hunt unexpected reloads first.

  • Upgrade self hosted Metabase to the vendor minimums 0.58.24 0.59.21 0.60.17 0.61.11 0.62.9 0.63.5 or later. Block api session reset password until done.

  • Wipe Metabase core session review API keys and admin accounts and rotate every connected warehouse credential if the 400 200 pattern exists.

  • Deploy the August Windows cumulative that remediates CVE-2026-68820 and reboot. Prioritize VDI jump boxes and developer endpoints.

  • Audit FortiOS FortiProxy for CVE-2024-55591 CVE-2025-24472 patch level and delete any forticloud sync super admin.

  • Review VDI SSL VPN authentication servers for unauthorized OTP handler or file changes. Treat MFA bypass as a credential incident not a phishing ticket.

  • Preserve Linux files with .GNRA and their timestamps before quarantine if Gunra is in scope. Notify CISA FBI before destructive cleanup.

  • Hunt DeadLock markers .dlock HOW RECOVER RECOVERY CHAT Polygon RPC to the published contracts and the Microsoft SHA 256.

  • Restrict or inventory internet facing GeoServer upgrade to 3.0.1 2.28.5 2.27.6. Monitor OGC filter requests containing jsonArrayContains.

  • Test offline immutable backups this week. Both Gunra and DeadLock delete or skip recovery paths on purpose.

  • Deploy the Microsoft August 2026 cumulative security patch across endpoints and domain controllers immediately.

  • Patch all Progress Kemp LoadMaster load balancers to resolve CVE-2026-8037 command injection flaws.

  • Restrict developer package installation workflows by enforcing ignore scripts on unverified external npm dependencies.

  • Implement FIDO2 WebAuthn hardware tokens across corporate identity providers to nullify voice phishing and AiTM token theft.

  • Block execution of unauthorized local binaries from user Temp and AppData directories via AppLocker or Application Control.

  • Scan package lockfiles and CI CD pipelines for indicators linked to the Shai Hulud CHAINDROP package list.

  • Deploy endpoint detection hunting queries for anomalous parent child relationships where low privileged processes spawn SYSTEM shells.

  • Audit external facing perimeter appliances and verify that administrative consoles are isolated from public ingress routing.

CONFIDENCE & LIMITATIONS

  • Exploitation status for CVE-2026-68820 CVE-2026-20349 CVE-2026-72898 High Microsoft CISA KEV Cisco CCCS Metabase vendor alignment

  • Gunra TTPs and DeadLock technical behavior High Multi agency advisory Microsoft TI primary

  • Progress Kemp LoadMaster CVE-2026-8037 High CISA KEV confirmed exploitation

  • Patch Tuesday totals Medium Krebs 398 Talos 421 SANS ISC 418 disagree on inclusion rules

  • Lazarus Operation Dream Job as operator of CVE-2026-68820 Low to medium Detailed consistent Check Point research echoed by secondary not independently stated by primary registry source this week

  • GeoServer in the wild Medium Probing reported by watchTowr noted by SANS ISC not KEV

  • UNC6671 and Shai Hulud campaign Medium to high Corroborated intelligence reporting

  • Kaspersky items Supplemental only Vendor only do not use as sole attribution

  • Empty primary desks this week Insufficient data Listed as insufficient data not proof of absence