SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefThursday, August 13, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Lazarus Exploits Windows Zero-Day in Defense Attacks | CRITICAL |
|
5 C2 IPs | 41 OTX IOCs | 34 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is dominated by the active exploitation of critical vulnerabilities, including a Windows local privilege escalation zero-day (CVE-2026-68820) leveraged by the North Korean Lazarus Group to deploy the ForestTiger backdoor, and a VMware vCenter directory-traversal flaw (CVE-2026-59310). Additionally, organizations face severe supply chain and platform risks from malicious LiteLLM PyPI packages and the stealthy "City-Forum" campaign targeting Salesforce and ServiceNow portals. Immediate patching and configuration audits are highly recommended to secure external-facing applications and internal systems. |
|
■ CRITICAL STORIES Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor North Korean state-sponsored actors are actively exploiting CVE-2026-68820 to target defense and aerospace firms, bypassing security controls to deploy the ForestTiger backdoor. |
Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset Attackers are abusing unauthenticated guest access to quietly enumerate and exfiltrate sensitive data from exposed Salesforce Experience Cloud and ServiceNow customer portals. |
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access Threat actors are actively exploiting CVE-2026-59310, a CVSS 9.8 directory-traversal vulnerability in Broadcom VMware vCenter, to establish persistent unauthorized access. |
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations A supply chain compromise of the LiteLLM PyPI package allowed threat actors to distribute credential-stealing malware, harvesting cloud keys, database passwords, and SSH keys. |
|
■ CVEs IDENTIFIED CVE-2026-68820 Microsoft Windows — Local Privilege Escalation / SYSTEM Access |
CVE-2026-59310 Broadcom VMware vCenter — Directory Traversal / Remote Access |
CVE-2026-71362 Adobe Commerce / Magento — Account Takeover / Hijacking |
CVE-2026-58231 SAP Commerce Cloud (Data Hub Adapter) — Unauthenticated Remote Code Execution |
|
■ THREAT ACTORS Lazarus Group | State-Sponsored (North Korea) |
Exploiting Windows zero-day CVE-2026-68820 in "Operation Dream Job" targeting defense and aerospace firms to deploy the ForestTiger backdoor. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploitation of VMware vCenter (CVE-2026-59310) and SAP Commerce Cloud (CVE-2026-58231). |
| T1068 | | Exploitation for Privilege Escalation | Lazarus Group exploiting Windows zero-day CVE-2026-68820; "Plug and Pwn" abusing Plug and Play. |
| T1195.002 | | Malicious Software Update | Supply chain compromise of LiteLLM on PyPI. |
| T1566.002 | | Spearphishing Link | Lazarus Group's "Operation Dream Job" targeting defense sector. |
| T1133 | | External Remote Services | "City-Forum" campaign exploiting unauthenticated guest access on Salesforce and ServiceNow. |
| T1176 | | Browser Extensions | 737 fake Chrome VPN extensions routing traffic through malicious SOCKS5 proxies. |
|
■ PATCH PRIORITY Microsoft Windows — Zero-day CVE-2026-68820 exploited in the wild by Lazarus Group — [BC] |
Broadcom VMware vCenter — CVE-2026-59310 directory-traversal actively exploited for remote access — [THN] |
SAP Commerce Cloud — CVE-2026-58231 CVSS 10.0 unauthenticated RCE vulnerability — [THN] |
Adobe Commerce / Magento — CVE-2026-71362 critical flaw exploited to hijack customer accounts — [BC] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Apply Microsoft's August Patch Tuesday updates immediately to patch the Windows zero-day CVE-2026-68820 exploited by Lazarus. |
| 2 | [P1] Patch Broadcom VMware vCenter immediately to address the actively exploited directory-traversal vulnerability CVE-2026-59310. |
| 3 | [P1] Update SAP Commerce Cloud (Data Hub Adapter) to resolve the CVSS 10.0 unauthenticated RCE vulnerability CVE-2026-58231. |
| 4 | [P1] Patch Adobe Commerce and Magento installations to remediate CVE-2026-71362 and prevent account hijacking. |
| 5 | [P2] Audit Salesforce Experience Cloud and ServiceNow guest portal configurations to disable unauthenticated access and prevent "City-Forum" data harvesting. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |