Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
North Korea’s Lazarus Group exploited a Windows zero-day in the AFD.sys driver as part of a fresh wave of its long-running Dream Job campaign, targeting defense and aerospace firms in France, Germany, Brazil, and India with fake recruiter outreach on LinkedIn. Victims were lured into opening a trojanized PDF viewer or a malicious archive that deployed a new backdoor called Troy, while a companion downloader used the flaw to gain SYSTEM privileges and load an updated version of the FudModule rootkit capable of tampering with Windows Smart App Control. The campaign hijacked compromised WordPress, SharePoint, and Roundcube servers for command-and-control traffic to blend in with legitimate web activity, and the exploited flaw has since been patched in Microsoft’s August update.
Critical VMware vCenter flaw actively exploited in 47 countries
A directory-traversal vulnerability in VMware vCenter’s Syslog server, rated a maximum severity of 9.8, is being actively exploited by unspecified attackers who have compromised 361 unique IP addresses across 47 countries, most heavily in Germany, the United States, Turkey, Iran, and France. The attackers use the flaw to gain code execution and then install a cron job running reverse SSH tooling to maintain persistent outbound access to compromised systems, a technique that can evade defenses focused on blocking inbound connections. Researchers note that because vCenter controls an organization’s entire virtualization estate, a single compromise can hand attackers leverage over every connected host, VM, and snapshot, and patching alone will not remove any persistence already established before the fix was applied.
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Microsoft’s August Patch Tuesday addressed 421 CVEs, including a use-after-free flaw in the afd.sys kernel-mode driver that has already been exploited in the wild to gain SYSTEM privileges without requiring user interaction. A second flaw affecting the User Profile Service was publicly disclosed and flagged as likely to be exploited soon, while a third bug in the Windows Container Isolation FS Filter Driver was also disclosed but considered less likely to see active attacks. The bulk of the fixes landed in Windows, Office, and SharePoint Server, with additional remote code execution bugs patched in the Windows DNS server, Deployment Services TFTP server, Microsoft QUIC, and HPC Pack.
Ransomware Attack disrupts Hospital Doors, Elevators, Ventilation and Air Conditioning in Canada
A ransomware attack against Winnipeg’s Health Sciences Centre, Manitoba’s largest hospital, disrupted facility-management systems including door access, elevators, heating, and air conditioning, though clinical operations and patient care reportedly continued uninterrupted. The incident illustrates how ransomware increasingly reaches beyond IT systems into interconnected operational technology that controls a building’s physical environment, with the hospital increasing security staffing at entrances while affected doors were restored. The attackers have not been publicly identified, and the disclosure came alongside a separate U.S.-South Korean government warning about the Gunra ransomware group, which has reportedly begun incorporating data-wiping capabilities into its attacks on healthcare, financial, and transportation targets.
LexisNexis pulls three services offline after suspicious server activity
LexisNexis took its Diligence, Newsdesk, and Metabase API products offline after detecting unusual activity on servers hosted and managed by a third-party vendor, choosing to disconnect from those systems to contain the issue while forensic investigators review what happened. The outage began the prior Wednesday and left corporate customers who rely on the tools for background checks and news monitoring without service for several days, with one affected customer saying they intend to seek compensation for the disruption. The company confirmed the incident is unrelated to a separate critical SQL injection vulnerability disclosed in the unrelated Metabase business-intelligence platform around the same time, which has already been linked to a data breach at laptop maker Framework.