CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Lazarus weaponized Windows zero-day CVE-2026-68820 against defense, aerospace and aviation targets in Operation Dream Job. The AFD.sys privilege-escalation flaw was exploited for weeks before Microsoft patched it, giving North Korean operators a path from a low-privileged foothold to kernel-level access.
After escalating privileges, the attackers deployed the Troy backdoor alongside FudModule and infrastructure associated with RelayShell. The activity reached organizations in Europe and India and combined targeted recruitment lures with post-compromise tooling designed for sustained access.
CISA ordered U.S. federal agencies to patch CVE-2026-68820 within two weeks. Organizations should prioritize the update while hunting for the initial access and follow-on malware that the kernel exploit requires rather than treating patch deployment alone as proof of containment.
Editorial: Recommended Actions
01
PRIORITY
Patch Microsoft Windows against CVE-2026-68820 immediately, prioritizing defense, aerospace and aviation environments. Lazarus is actively using this AFD.sys flaw after gaining a low-privileged foothold to escalate privileges and deploy the Troy backdoor; CISA gave U.S. federal agencies two weeks to apply the fix.
02
PRIORITY
Apply Metabase remediation for CVE-2026-72898 and investigate exposed instances for unauthorized administrator access. A single unauthenticated request to the password-reset endpoint can grant full administrative control, exposing connected databases, data warehouses and credential stores; five companies reportedly lost customer data before public remediation.
03
PRIORITY
Restrict network exposure of VMware vCenter Syslog servers and investigate affected systems for reverse_ssh processes and malicious cron jobs while addressing CVE-2026-59310. Attackers are actively exploiting the CVSS 9.8 directory-traversal flaw for arbitrary code execution and persistence, with activity affecting 361 victim IPs in 47 countries.
04
PRIORITY
Ensure FortiOS and FortiProxy appliances are no longer vulnerable to CVE-2024-55591 or CVE-2025-24472, then examine potentially exposed environments for stolen credentials, lateral movement and exfiltration staging. Gunra affiliates exploit these authentication bypasses before bypassing MFA, stealing data and deploying ransomware against government, healthcare and critical infrastructure organizations.
05
PRIORITY
Audit Salesforce Experience Cloud and ServiceNow portals for guest-accessible interfaces and search endpoints that expose enterprise data. City-Forum has targeted these surfaces since at least March 2025, abusing misconfigured guest access rather than a software vulnerability; banks, public-sector bodies, telecoms and enterprise software organizations are among the targets.
ROUNDTABLE
Expert Panel Discussion
12 AI experts analyzed this briefing across 3 turns of structured debate
12Agents19Messages30mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_