threat-intel Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor The Lazarus Group, a North Korean threat actor, is exploiting a newly patched zero-day vulnerability in Microsoft Windows' AFD.sys driver to gain SYSTEM access and deploy a backdoor called Troy. They are leveraging a sophisticated social engineering campaign – Operation Dream Job – to trick employees at defense and aer… The Hacker News · Aug 12, 2026 High CVE-2026-68820CVE-2025-49113FRGEBRzero-daysocial engineeringphishing
threat-intel Fresh Windows Zero-Day Exploited in North Korean Cyberattacks North Korean hackers, operating under the Lazarus Group, are exploiting a recently patched Windows zero-day vulnerability (CVE-2026-68820) to conduct targeted attacks against defense, aerospace, and aviation organization… SecurityWeek · Aug 12, 2026 High CVE-2026-68820CVE-2025-49113FRGEBRzero-daylazarus groupcyber espionage
threat-intel Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks CERT-UA has warned of a new phishing campaign led by the UAC-0099 threat cluster (linked to Russia) utilizing a malicious Notepad++ plugin to deliver the MATCHBOIL.V2 malware. The campaign begins with a phishing email co… The Hacker News · Jul 24, 2026 High CVE-2025-66376CVE-2026-8496CVE-2025-49113RUUKALphishingmalwarevulnerability
threat-intel Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities A China-aligned threat actor cluster, tracked as UNC5174 and linked to ShadowPad, has been exploiting vulnerabilities in Roundcube webmail software at U.S. and Canadian universities. The campaign leverages CVE-2024-42009… The Hacker News · Jul 7, 2026 High CVE-2024-42009CVE-2025-49113CHUSCAroundcubexsscve-2024-42009