A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

2026-08-13T02:51:40Z9eec767688db78f9bc0bb1981306872ff1ecf0b91a2103637cd11d51699aae38
CVE-2026-68820AI governanceChromeLazarus GroupMicrosoft Patch TuesdayNorth KoreaOT securityOperation Dream JobSalesforceServiceNowSignalWindowsactive exploitationcloud securitydata exposureencryptionfake job offersguest user exposurepenetration testingphishingprivilege escalationspearphishingtrojanized softwarezero-day

What happened

Help Net Security coverage includes a 17-month campaign exploiting guest-user exposure in Salesforce and ServiceNow portals, a Lazarus fake-job campaign using trojanized PDF software and a Windows zero-day, and Microsoft’s August 2026 Patch Tuesday addressing more than 400 vulnerabilities. The actively exploited Windows AFD.sys privilege-escalation flaw, CVE-2026-68820, is the most urgent item. Other entries cover Signal automatic key verification, AI governance and security products, continuous penetration testing, OT tampering detection, and Chrome protections against abusive notifications.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
9eec767688db78f9bc0bb1981306872ff1ecf0b91a2103637cd11d51699aae38
Enrichment time
2026-08-13T02:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months · Baitaphish