Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

2026-08-13T01:23:58Z0094553163cf7d4a9d51de8d4e52315a7315634720fa62e507287d1795fb3dc3
CVE-2026-20349CVE-2026-48362CVE-2026-50656CVE-2026-55040CVE-2026-58231CVE-2026-59310CVE-2026-68820APTAdobe ColdFusionAndroid botnetChrome extensionsCisco ASACisco FTDDDoSLazarus GroupMicrosoft SharePointNorth KoreaPyPISAP Commerce CloudSYSTEM accessVMware vCenterWindowsactive exploitationarbitrary code executioncredential theftcritical infrastructureindustrial control systemsmalwareprivilege escalationransomwaresupply-chain attackzero-day

What happened

The feed reports widespread high-impact cybersecurity activity, including Lazarus exploitation of a Windows zero-day, active exploitation of VMware vCenter and Cisco firewall vulnerabilities, critical Adobe and SAP flaws, SharePoint unauthenticated RCE, malicious packages and browser extensions, ransomware and botnet campaigns, supply-chain compromises, and attacks against industrial infrastructure. Several items describe active exploitation, SYSTEM-level compromise, arbitrary code execution, credential theft, or operational disruption.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
0094553163cf7d4a9d51de8d4e52315a7315634720fa62e507287d1795fb3dc3
Enrichment time
2026-08-13T01:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.