A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months
2026-08-12T20:51:50Z•a81eecde97bf522dd729e43bd1ee4bd7a192b691c1ca447d3f9047d3f1d318cd
CVE-2026-68820AndroidChromeLazarus GroupNorth KoreaOT securityOperation Dream JobSalesforceServiceNowWindowsactive exploitationcloud securitydata exposureenterprise securityfake job offersguest user exposurepatch managementphishingprivilege escalationsocial engineeringtrojanized softwarezero-day
What happened
Help Net Security reports on a 17-month campaign extracting records from exposed Salesforce and ServiceNow portals, a Lazarus fake-job campaign using trojanized PDF software and a Windows zero-day, and Microsoft’s August 2026 Patch Tuesday addressing more than 400 vulnerabilities. The actively exploited flaw, CVE-2026-68820, is a Windows AFD.sys use-after-free vulnerability enabling low-privileged local attackers to elevate privileges to SYSTEM. Other items cover Signal automatic key verification, AI governance and security products, continuous penetration testing, OT tampering detection, and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- a81eecde97bf522dd729e43bd1ee4bd7a192b691c1ca447d3f9047d3f1d318cd
- Enrichment time
- 2026-08-12T20:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.