Forum Discussion
Tenable Security Intel Brief: Lazarus adds a Windows zero-day to its resume
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team.
This week, Check Point Research details what Lazarus Group was willing to spend to make a single fake job offer land, and what that price says about the targets they wanted.
Lazarus burned a Windows zero-day on fake job offers to defense firms →
Brief: Check Point Research attributed a fake job-offer campaign to Lazarus Group. Attackers used a Windows zero-day against defense, aerospace, and aviation firms in France, Germany, Brazil, and India.
Intel: Lazarus exploited CVE-2026-68820, a flaw in a core Windows networking component, to take full control of the machine and deploy FudModule v3.1, a rootkit (malware that hides itself) that switches off Windows' own security logging so defenders lose visibility. The exploit payload was protected with post-quantum encryption (built to resist future quantum computers) and ran in memory, leaving no file behind. Command-and-control traffic ran through at least 17 hijacked third-party servers, including Roundcube webmail instances compromised via CVE-2025-49113. Microsoft patched CVE-2026-68820 in its August 2026 Patch Tuesday.
Why it matters: Here's the resume: Windows zero-day, post-quantum exploit encryption, a rootkit that kills logging, and 17 hijacked relay servers. That's what Lazarus spent to reach defense firms building drones, surveillance sensors, and robotics.
SAP Commerce Cloud CVSS 10 flaw targeted three days after patch →
Brief: SAP patched CVE-2026-58231, a maximum severity flaw (CVSS 10) in SAP Commerce Cloud (formerly SAP Hybris) that lets an attacker act without authorization, enabling unauthenticated remote code execution, on August 11.
Intel: CVE-2026-58231 is in the Data Hub Adapter extension of SAP Commerce Cloud. The flaw lets a remote, unprivileged attacker abuse a built-in login component to slip malformed input past the platform's checks, resulting in arbitrary code execution. SAP shipped Security Note 3771065 on August 11. Defused honeypots recorded exploitation attempts on August 14, independently confirmed by threat-intelligence tracker KEV Intelligence: two attempts, one attacker IP. A public proof-of-concept appeared August 15. CISA has not added this flaw to its Known Exploited Vulnerabilities catalog as of August 18.
Why it matters: Exploitation attempts began within three days of the patch. A public proof-of-concept landed the day after that, on day four. For a CVSS 10 flaw that needs no credentials and no user interaction, these four days sit entirely inside the window enterprise change-control cycles need just to begin.
Kimsuky sets up offline AI environments on its own attack servers →
Brief: Genians found that Kimsuky, a North Korean threat group operating under the Reconnaissance General Bureau, built and operated local large language models (LLMs), typically cut off from the internet, on its own command-and-control infrastructure.
Intel: Logs from Kimsuky's C2 infrastructure showed Ollama and GPT4All, free tools for running AI models offline, installed and used. Ollama left auto-generated key files confirming a launch; GPT4All carried a localdocs_v3.db, the database a feature creates to let the AI answer questions from a private document set. Genians also found speech-to-text tools and building blocks for adding AI to its own software. Genians assesses the activity as a "research and knowledge acquisition stage," integrating existing AI rather than training new models, and the offline stack has not been observed against a victim.
Why it matters: Running AI locally removes the provider oversight that usage policies and takedowns depend on. The attack steps beneath it (booby-trapped shortcuts, hidden scripts, recurring scheduled tasks, GitHub-disguised traffic) read the same no matter how clean the output looks. As local models gain parity with frontier models, defenders stand to lose insight into threat actor playbooks.
One IP scraped Salesforce and ServiceNow portals for seventeen months →
Brief: A single-IP campaign has been pulling records from misconfigured Salesforce and ServiceNow customer portals that are public and require no login, since at least March 2025, with no vulnerability exploited and the same infrastructure throughout.
Intel: Reco traced the campaign to one IP, a Contabo VPS in Germany, running a single custom-built scanning tool that always looked exactly the same. The tooling pulled records through the data-access channels behind these portals, including one in ServiceNow that had barely been documented; the single busiest target logged more than 560,000 events from that one address over the life of the campaign. ServiceNow confirmed no platform compromise; Reco's conclusion: "every byte the attacker retrieved was something a site owner had exposed to anonymous users."
Why it matters: Nothing was exploited, so nothing was flagged. The 560,000 logged events at one target sat inside ordinary guest portal traffic, undetected, on infrastructure that has stood for seventeen months. The visibility gap sits on the surface organizations hand to anonymous visitors and then stop watching.
Stat of the week: 1.7 billion
The number of credentials harvested by infostealer malware across more than 7.4 million compromised systems in the first half of 2026 alone, according to the Flashpoint Global Threat Intelligence Report, Midyear Edition.
Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.