Lazarus-linked attacks exploit Windows CVE-2026–68820 as a zero-day to gain SYSTEM access and deploy Troy against defense and aerospace firms.
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution.
The vulnerability, assigned the CVE identifier CVE-2026–58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation.
“SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation,” according to a description of the flaw on CVE.org.
Security researchers have disclosed new “Plug and Pwn” attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges.
The research, presented at DEF CON 34 by security researchers Alejandro Hernando and Borja Martínez, exploits how Windows automatically identifies new connected hardware, locates matching driver packages, and installs vendor software as the NT AUTHORITY\SYSTEM account.
By using software to emulate USB devices, the researchers found they could force Windows to install signed vendor packages containing exploitable components or weaknesses that can be abused to gain SYSTEM privileges.
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026–68820) to target defense-sector companies as part of the Operation Dream Job campaign.
Microsoft addressed the flaw in this month’s Patch Tuesday security updates, marking it as actively exploited in the wild. Researchers found that the Lazarus threat group has been leveraging it since early July.
Microsoft says that the vulnerability is a “use-after-free in Windows Ancillary Function Driver for WinSock (AFD.sys)” that allows an attacker to increase their local privileges.
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal card data and send it to attackers in real time.
In an incident investigated by the cybersecurity company Group-IB, a fraudster impersonated a bank employee and called the victim under the pretense of a problem with their payment card.
During the call, the threat actor instructed the victim to sideload the SpyNote RAT disguised as a legitimate app and grant it Accessibility Service permissions, giving the attacker remote access to the Android device.
Attempts to exploit a critical vulnerability (CVE-2026–71362) in Adobe’s Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.
The flaw is described as an incorrect authorization vulnerability that could be leveraged to “gain elevated access to sensitive resources” without authentication and is one of the seven issues that Adobe addressed in a security update yesterday.
Although the software vendor states in the advisory that it is not aware of exploits in the wild for any of the fixed flaws, eCommerce security company Sansec says that its Shield web application firewall (WAF) is already blocking CVE-2026–71362 exploitation attempts.