~/greenteam/nerd

Thursday, August 13, 2026

Daily digest

Two North Korea-linked Windows zero-day stories (a Lazarus/Operation Dream Job campaign and a related CISA patch directive) dominate today's cyber news alongside a wave of actively-exploited enterprise software CVEs (SharePoint, VMware vCenter, Adobe Commerce) — patch management should be the priority today.

cybersec The Hacker News

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors are actively exploiting CVE-2026-55040 (CVSS 9.1), a critical SharePoint security feature bypass caused by weak authentication, after proof-of-concept code was released publicly. Microsoft patched the flaw in its July 2026 Patch Tuesday updates.

Why it matters: If any on-premises SharePoint Server instances remain in your hybrid environment (as opposed to SharePoint Online in GCC High), confirm the July patch is applied immediately — public PoC means exploitation will spread fast.

cybersec The Hacker News

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Check Point Research attributed exploitation of a newly patched Windows zero-day to North Korea's Lazarus Group, used to deliver a previously unseen backdoor targeting defense and aerospace companies in France, Germany, Brazil, and India. The activity is part of the long-running Operation Dream Job espionage campaign, which lures victims through fake job applications.

Why it matters: Defense-sector targeting via job-application lures is a direct threat to CMMC L2 contractors; ensure the underlying zero-day is patched fleet-wide via Intune and brief staff on fake recruiter/job-offer phishing.

cmmc The Record

CISA Gives Federal Agencies Two Weeks to Patch Microsoft Bug Exploited in DPRK Campaign

CISA has added a Microsoft vulnerability exploited in a long-running North Korean job-application-themed campaign to its Known Exploited Vulnerabilities catalog, giving federal agencies two weeks to patch. Researchers disclosed the bug to Microsoft after examining the campaign targeting job seekers.

Why it matters: Even outside FCEB scope, CMMC L2 organizations should treat CISA KEV additions as de facto patch deadlines and document remediation timelines for 800-171 vulnerability management evidence.

cybersec Ars Technica Security

Terabytes of Credentials Leaked in Massive Supply-Chain Attack

A compromised AI package scraped and exfiltrated terabytes of credentials from roughly 2,500 users, according to Ars Technica. The incident represents one of the larger AI-tooling supply-chain compromises reported this year.

Why it matters: If your self-hosted AI stack pulls packages from public registries (PyPI, npm, Hugging Face), audit dependencies for this compromised package and rotate any credentials that may have touched affected tooling.

cybersec The Register

Microsoft-Vendetta Hacker Has a New Zero-Day That Gives SYSTEM Privileges on Fully Patched Windows

A researcher known for repeatedly targeting Microsoft has disclosed a new zero-day privilege escalation flaw that grants SYSTEM-level access even on fully patched Windows systems. Details were released ahead of an official Microsoft fix.

Why it matters: Expect an out-of-band Microsoft advisory; monitor for an emergency patch and be ready to push it to the Intune-managed Windows 11 fleet outside the normal Patch Tuesday cycle.

infrastructure The Hacker News

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Security firm QUIRSO reports active exploitation of CVE-2026-59310 (CVSS 9.8), a directory-traversal flaw in Broadcom VMware vCenter Server that allows remote code execution for attackers with network access. Patches for the vulnerability were previously released by Broadcom.

Why it matters: Not directly applicable to Nutanix AHV, but if any legacy VMware vCenter instances remain in the environment (e.g., during a migration), patch immediately given active exploitation.

cybersec BleepingComputer

Plug and Pwn Attack Uses Fake USB Devices for Windows SYSTEM Access

Security researchers disclosed "Plug and Pwn," a technique that abuses the Windows Plug and Play feature to trick systems into installing vulnerable or insecure vendor software, resulting in SYSTEM-level privileges. The attack requires physical or logical USB device emulation.

Why it matters: Consider tightening Intune USB device restriction policies and reviewing which vendor drivers are auto-installed via Plug and Play on managed Windows 11 endpoints.

infrastructure The Register

AWS Key Exposed in JavaScript May Have Lit Way to Beacon's Charity Data

CRM provider Beacon confirmed a customer database was copied and likely downloaded in readable form, after an AWS access key was found exposed in client-side JavaScript. The exposure may have provided attackers the entry point into the charity-sector customer data.

Why it matters: A reminder to audit any public-facing web apps for hardcoded AWS credentials, particularly relevant when managing AWS GovCloud front-end services or SaaS integrations.

infrastructure AWS Security Blog

AWS IAM Role Manager Rethinks the Starting Point for IAM Roles

AWS Security Blog detailed a new IAM Role Manager feature designed to simplify creation of least-privilege IAM roles for AWS services acting on a user's behalf. The tool aims to reduce manual policy-writing errors during role setup.

Why it matters: Simplifying least-privilege IAM role creation directly supports NIST 800-171 access control requirements for AWS GovCloud workloads and reduces audit friction during CMMC assessments.

cmmc NextGov

NIST Wants to Outfit the National Vulnerability Database with AI

NIST is exploring how to use artificial intelligence to modernize reporting and response processes for the National Vulnerability Database. The effort is aimed at addressing longstanding backlogs and delays in CVE analysis and enrichment.

Why it matters: NVD data quality and turnaround directly feed vulnerability scanning and POA&M processes required for NIST 800-171/CMMC L2 compliance; faster, more accurate enrichment could ease audit prep.

cmmc NextGov

DISA Sets Release Date for Follow-On Cloud Solicitation

The Defense Information Systems Agency announced a release date for the successor to its $9 billion cloud computing contract vehicle, aiming to expand participation beyond the four major hyperscalers currently on the vehicle.

Why it matters: Expansion beyond the big four hyperscalers could open new DoD-approved cloud options; worth tracking if your organization holds or pursues DoD contracts requiring FedRAMP/IL cloud environments alongside AWS GovCloud.

cybersec Dark Reading

Long-Running Data Theft Campaign Targeting Salesforce, ServiceNow

Dubbed "City-Forum," a data theft campaign active since at least March 2025 has used custom tooling to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals, targeting organizations across multiple sectors.

Why it matters: Review any Salesforce Experience Cloud or ServiceNow customer-facing portal configurations for anonymous/guest access permissions that could expose sensitive data.