Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
2026-08-12T19:24:00Z•63f07589e297eb3eca64bbd907b9027750e5e8925ef295b37728445ee79fa373
CVE-2026-20349CVE-2026-48362CVE-2026-50656CVE-2026-55040CVE-2026-58231CVE-2026-59310CVE-2026-68820AI-securityAPT44Adobe-ColdFusionCisco-ASADDoSLazarusMicrosoft-SharePointSAP-Commerce-CloudSandwormVMware-vCenterWindowsactive-exploitationbrowser-extensionscloud-securitycredential-theftcritical-infrastructureindustrial-control-systemsmalwarenation-stateprivilege-escalationransomwareremote-code-executionsupply-chain-compromisezero-day
What happened
The feed reports active exploitation and disclosure of multiple critical vulnerabilities across Windows, VMware vCenter, SAP Commerce Cloud, Adobe ColdFusion, Cisco firewalls, and Microsoft SharePoint. It also covers nation-state campaigns by Lazarus and Sandworm-linked actors, ransomware and botnets, malicious software supply-chain releases, compromised browser extensions, AI tooling abuse, and attacks against industrial infrastructure. Several vulnerabilities enable unauthenticated remote code execution or SYSTEM-level access, while others are confirmed exploited in the wild.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 63f07589e297eb3eca64bbd907b9027750e5e8925ef295b37728445ee79fa373
- Enrichment time
- 2026-08-12T19:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.