Daily Security Intel

Archives
Log in
Subscribe
August 13, 2026

[SecurityIntel] 13 Aug | Lazarus Exploits Windows Zero-Day in Defense Attacks

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Thursday, August 13, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Lazarus Exploits Windows Zero-Day in Defense Attacks

CRITICAL

5

C2 IPs

41

OTX IOCs

34

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by the active exploitation of critical vulnerabilities, including a Windows local privilege escalation zero-day (CVE-2026-68820) leveraged by the North Korean Lazarus Group to deploy the ForestTiger backdoor, and a VMware vCenter directory-traversal flaw (CVE-2026-59310). Additionally, organizations face severe supply chain and platform risks from malicious LiteLLM PyPI packages and the stealthy "City-Forum" campaign targeting Salesforce and ServiceNow portals. Immediate patching and configuration audits are highly recommended to secure external-facing applications and internal systems.

■ CRITICAL STORIES

INFO#1

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

North Korean state-sponsored actors are actively exploiting CVE-2026-68820 to target defense and aerospace firms, bypassing security controls to deploy the ForestTiger backdoor.

INFO#2

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

Attackers are abusing unauthenticated guest access to quietly enumerate and exfiltrate sensitive data from exposed Salesforce Experience Cloud and ServiceNow customer portals.

INFO#3

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors are actively exploiting CVE-2026-59310, a CVSS 9.8 directory-traversal vulnerability in Broadcom VMware vCenter, to establish persistent unauthorized access.

INFO#4

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

A supply chain compromise of the LiteLLM PyPI package allowed threat actors to distribute credential-stealing malware, harvesting cloud keys, database passwords, and SSH keys.

■ CVEs IDENTIFIED

CVE-2026-68820

Microsoft Windows — Local Privilege Escalation / SYSTEM Access

Critical

CVE-2026-59310

Broadcom VMware vCenter — Directory Traversal / Remote Access

Critical

CVE-2026-71362

Adobe Commerce / Magento — Account Takeover / Hijacking

Critical

CVE-2026-58231

SAP Commerce Cloud (Data Hub Adapter) — Unauthenticated Remote Code Execution

Critical

■ THREAT ACTORS

Lazarus Group

State-Sponsored (North Korea)

Exploiting Windows zero-day CVE-2026-68820 in "Operation Dream Job" targeting defense and aerospace firms to deploy the ForestTiger backdoor.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploitation of VMware vCenter (CVE-2026-59310) and SAP Commerce Cloud (CVE-2026-58231).
T1068
Exploitation for Privilege Escalation | Lazarus Group exploiting Windows zero-day CVE-2026-68820; "Plug and Pwn" abusing Plug and Play.
T1195.002
Malicious Software Update | Supply chain compromise of LiteLLM on PyPI.
T1566.002
Spearphishing Link | Lazarus Group's "Operation Dream Job" targeting defense sector.
T1133
External Remote Services | "City-Forum" campaign exploiting unauthenticated guest access on Salesforce and ServiceNow.
T1176
Browser Extensions | 737 fake Chrome VPN extensions routing traffic through malicious SOCKS5 proxies.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Microsoft Windows — Zero-day CVE-2026-68820 exploited in the wild by Lazarus Group — [BC]

[P1 PATCH NOW]≤24h

Broadcom VMware vCenter — CVE-2026-59310 directory-traversal actively exploited for remote access — [THN]

[P1 PATCH NOW]≤24h

SAP Commerce Cloud — CVE-2026-58231 CVSS 10.0 unauthenticated RCE vulnerability — [THN]

[P1 PATCH NOW]≤24h

Adobe Commerce / Magento — CVE-2026-71362 critical flaw exploited to hijack customer accounts — [BC]

■ RECOMMENDED ACTIONS TODAY

1[P1] Apply Microsoft's August Patch Tuesday updates immediately to patch the Windows zero-day CVE-2026-68820 exploited by Lazarus.
2[P1] Patch Broadcom VMware vCenter immediately to address the actively exploited directory-traversal vulnerability CVE-2026-59310.
3[P1] Update SAP Commerce Cloud (Data Hub Adapter) to resolve the CVSS 10.0 unauthenticated RCE vulnerability CVE-2026-58231.
4[P1] Patch Adobe Commerce and Magento installations to remediate CVE-2026-71362 and prevent account hijacking.
5[P2] Audit Salesforce Experience Cloud and ServiceNow guest portal configurations to disable unauthenticated access and prevent "City-Forum" data harvesting.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 14 Aug | Active VMware and Windows Zero-Day Exploitations Surge Older → [SecurityIntel] 12 Aug | Active Zero-Day and SharePoint RCE Patched
Powered by Buttondown, the easiest way to start and grow your newsletter.