๐จ ACTIVE EXPLOITATION
-
Lazarus Exploited Windows AFD.sys Zero-Day to Deploy ForestTiger Lazarus exploited a Windows zero-day to deploy ForestTiger.
- Lazarus targeted defense, aerospace, and aviation organizations in Europe, India, Brazil, and elsewhere.
- Windows AFD.sys contained CVE-2026-68820, a use-after-free flaw enabling SYSTEM-level privilege escalation.
- Fake job offers delivered encrypted ZIPs containing PDF viewers, malicious libmupdf.dll, and concealed payloads.
- MISTPEN used Microsoft Graph and OneDrive to retrieve modules before deploying FudModule v3.1, ForestTiger, or Troy.
- Affected Windows 11 builds included 26100 and 26200; reported SHA-256 IOC: 72dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289. ๐ Source: gendigital.com ยท ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
Malicious LiteLLM PyPI Releases Potentially Exposed 2,500 Organizations Malicious LiteLLM releases potentially exposed thousands of organizations and CI/CD pipelines.
- LiteLLM users, AI companies, enterprises, SaaS providers, and cybersecurity vendors were potentially exposed.
- PyPI versions 1.82.7 and 1.82.8 could steal cloud credentials, repository tokens, SSH keys, Kubernetes tokens, database passwords, and LLM API keys.
- Attackers compromised the Trivy scanner and used an unpinned CI dependency to publish poisoned LiteLLM releases on March 24, 2026.
- A malicious Python .pth file executed at interpreter startup and searched environment variables, files, process memory, cloud metadata, and Kubernetes paths.
- CloudSEK mapped potential exposure to 2,500+ organizations and 434,000 CI/CD pipelines; reported IOCs include SANDCLOCK and GitHub repositories tpcp-docs and docs-tpcp. ๐ Source: cloudsek.com ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
๐ต๏ธ RESEARCH & DEEP DIVES
-
ShieldBreak PoC Claims to Bypass Microsoft Defender Fix for SYSTEM Access A researcher released a PoC claiming to bypass Microsoft's Defender fix for RoguePlanet.
- Microsoft Defender on Windows 11 25H2 and Windows Server 2025 is reportedly affected.
- ShieldBreak targets the Defender privilege-escalation flaw CVE-2026-50656, known as RoguePlanet.
- The PoC reportedly exploits Defender file-handling behavior to obtain local SYSTEM privileges.
- The code includes Warden.dll, Report.wer, and eicar_com.zip; Windows 10 is described as vulnerable but unsupported by the PoC.
- The claimed bypass and 100% success rate have not been independently verified. ๐ Source: github.com ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
ClickFix campaign deploys CNCMachineRMS RAT through signed IBM SPSS IDE A ClickFix campaign is deploying the CNCMachineRMS remote-access trojan.
- Windows users are targeted through ClickFix by abusing IBM SPSS WinWrap Basic IDE, WinWrapIDE.exe.
- CNCMachineRMS is a 1.14 MB x64 RAT with shell, file management, screen capture, local-account backdoor, seven persistence methods, and payload execution.
- The signed IDE loads dropped DLLs through COM; four decoys invoke BabaDeda shellcode via the EnumTimeFormatsEx callback.
- The RAT has no import table, resolves APIs by hash, builds strings at runtime, and uses an obfuscated HelperStandardizationApplication.bin configuration.
- C2 indicators include notepadreleased[.]com and 85[.]158.110[.]78 over TCP/443, with 600-second beaconing. ๐ Source: levelblue.com ยท ๐ Coverage: gbhackers.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
-
Google-Themed 'New Audio MSG' Phishing Campaign Steals Account Credentials A phishing campaign uses fake voicemail emails to steal Google account credentials.
- Google Workspace and Google Voice users are targeted through work email.
- The campaign harvests credentials on a fake Google-themed sign-in page.
- A "Play Audio" link sends recipients through tracking and redirect services before loading the phishing page.
- The recipient's email address is Base64-encoded in the URL fragment for page personalization.
- IOCs include sendgrid[.]net, rdnjfgli.r.ap-northeast-1.awstrack[.]me, gm2.drr[.]accoderkubes[.]com/workspace/googlev.html, and spy.mwork801[.]com. ๐ Source: x.com ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
๐ ADVISORIES
-
SonicWall Patches Critical Flaws in Discontinued GMS Platform SonicWall patched critical unauthenticated RCE and data-disclosure flaws in discontinued GMS.
- SonicWall GMS Virtual Appliance and Windows versions 9.5.1 and earlier are affected.
- CVE-2026-66147 enables unauthenticated remote code execution through command injection.
- CVE-2026-66145 allows sensitive data disclosure through a zip slip attack.
- SonicWall reported no known exploitation in the wild. ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
-
SAP Commerce Cloud Data Hub Flaw Enables Unauthenticated Code Execution ๐ Source: support.sap.com
๐ CVEs & KEV
- CVE-2025-41769 โ CVSS 9.3 โ Unauthenticated Buffer Overflow in PROFINET ServiceThe device's PROFINET serv...
- CVE-2025-41770 โ CVSS 8.7 โ Unauthenticated Denial of ServiceAn unauthenticated denial-of-service vulnera...