A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months
2026-08-13T02:51:40Z•9eec767688db78f9bc0bb1981306872ff1ecf0b91a2103637cd11d51699aae38
CVE-2026-68820AI governanceChromeLazarus GroupMicrosoft Patch TuesdayNorth KoreaOT securityOperation Dream JobSalesforceServiceNowSignalWindowsactive exploitationcloud securitydata exposureencryptionfake job offersguest user exposurepenetration testingphishingprivilege escalationspearphishingtrojanized softwarezero-day
What happened
Help Net Security coverage includes a 17-month campaign exploiting guest-user exposure in Salesforce and ServiceNow portals, a Lazarus fake-job campaign using trojanized PDF software and a Windows zero-day, and Microsoft’s August 2026 Patch Tuesday addressing more than 400 vulnerabilities. The actively exploited Windows AFD.sys privilege-escalation flaw, CVE-2026-68820, is the most urgent item. Other entries cover Signal automatic key verification, AI governance and security products, continuous penetration testing, OT tampering detection, and Chrome protections against abusive notifications.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 9eec767688db78f9bc0bb1981306872ff1ecf0b91a2103637cd11d51699aae38
- Enrichment time
- 2026-08-13T02:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.