BoletimSecAugust 13, 2026🇵🇹Translated from Portuguese

Lazarus Group Exploits Windows Kernel Zero-Day CVE-2026-68820 to Deploy FudModule Rootkit

The North Korean Lazarus group is actively exploiting a zero-day vulnerability in the Windows kernel to obtain SYSTEM privileges and deploy the FudModule rootkit. The flaw, identified as CVE-2026-68820, was patched by Microsoft on 11 August.

The vulnerability affects afd.sys, the driver that handles network functions and socket management in Windows. Exploitation requires the attacker to already possess the ability to execute code with limited privileges on the target machine. From that position, the bug enables escalation to SYSTEM rights, granting extensive control over the operating system.

The campaign is part of Operation Dream Job, a long-running espionage operation that relies on fabricated job offers aimed at specialists in defense, aerospace, and aviation. Activity has been observed in Brazil, Europe, and India. Targets are lured into opening tampered PDF viewers or specially crafted files.

The attack chain begins with the MISTPEN downloader, which gathers basic system information before delivering the zero-day exploit. After privilege escalation, FudModule interferes with Windows telemetry mechanisms and reduces visibility for EDR solutions. The latest variant can also manipulate Smart App Control to further weaken additional protections.

Organizations are advised to apply the August Windows security updates immediately and to strengthen monitoring of files associated with fake employment opportunities.

Related articles

BoletimSecState-Sponsored & APT

Iranian Hackers Disable Safety Alarms in US Industrial Control Systems

Iranian threat actors have been compromising internet-exposed industrial controllers across the United States since at least March 2026, modifying alarm and safety shutdown logic in critical infrastructure. The campaign has targeted government organizations and operators in the water, wastewater, and energy sectors, resulting in operational disruptions and financial losses. Attackers focus on devices with insecure remote access, weak credentials, or default configurations rather than exploiting zero-day vulnerabilities. Targeted hardware includes Rockwell CompactLogix and Micro850 controllers, Schneider BMX P34 and Modicon M340 PLCs, and Siemens S7-1200 models. Operators use rented foreign infrastructure and legitimate programming software to download, alter, and re-upload control logic projects. In at least one case, malicious code maintained normal operations while introducing instructions that bypassed safe operational limits and altered data displayed on HMI and SCADA interfaces. The tactics closely resemble prior activity attributed to the CyberAv3ngers group linked to Iran’s Islamic Revolutionary Guard Corps, though direct attribution remains unconfirmed.

Security NEXTState-Sponsored & APT

Russian State-Supported Group LAUNDRY BEAR Exploits Zero-Day CVE-2025-66376 in Zimbra Collaboration Suite

Synacor’s Zimbra Collaboration Suite was targeted in a zero-day campaign by the Russian state-backed threat actor known as LAUNDRY BEAR. The stored cross-site scripting flaw in the webmail stylesheet handler allowed attackers to steal past emails simply by having victims view a specially crafted HTML message. No user interaction beyond opening the email was required for JavaScript execution in the browser. On 23 July 2026, sixteen countries including the United States, European nations and Australia issued a joint advisory signed by twenty-seven agencies such as NSA, FBI and CISA. The vulnerability received CVE-2025-66376 and a CVSS v3.1 base score of 7.2, rated High. Analysts assess the campaign focused on intelligence collection against Western government and corporate targets.

安全客State-Sponsored & APT

Russian Intelligence Hijacks Exposed Security Cameras in Europe and Ukraine for Military Surveillance

Dutch intelligence agencies AIVD and MIVD have revealed that Russian military intelligence is systematically compromising internet-connected security cameras across Europe and Ukraine. The attackers scan for exposed devices using brand fingerprints, then log in with default passwords and outdated firmware without needing zero-day exploits. In Ukraine, live camera feeds are used not only for reconnaissance of military transport routes and weapon deliveries but also to directly support targeting of Ukrainian forces and equipment. Censys identified over 87,000 vulnerable cameras in the EU, NATO countries, and Ukraine, with more than 4,000 located in Ukraine alone. While the actual number of confirmed compromises is smaller, the cameras are strategically positioned along key military logistics routes. The agencies issued basic but critical recommendations including disabling public exposure, changing default credentials, and applying patches for known vulnerabilities such as CVE-2016-7407 and CVE-2021-39275.

securitylab_nState-Sponsored & APT

US Accuses Russian Cybersecurity Specialist D.O. of Void Blizzard Attacks on European Governments and US Companies, Kaspersky Ties Emerge

American authorities have charged Russian information security specialist D.O. with participating in cyberattacks by the Void Blizzard group, also known as Laundry Bear, targeting NATO-aligned European government agencies and at least 11 US companies since 2023. D.O., who previously held a senior position at one of Russia’s largest cybersecurity firms widely identified as Kaspersky, did not plead guilty during a court hearing in Boston. The US Department of Commerce banned the company’s software in 2024 over national security concerns, while European agencies had issued similar warnings earlier. Prosecutors also linked D.O. to a Nizhny Novgorod IT company where he served as deputy director from 2024, although his earlier Kaspersky employment was confirmed through salary records and a former colleague rather than the indictment itself. D.O. graduated from Bauman Moscow State Technical University with a degree in information security, an institution previously flagged by European journalists as a potential training ground for state-linked operatives. Experts note that movement between commercial cybersecurity roles and intelligence structures occurs across countries, but D.O.’s guilt remains to be proven in court.