TL;DR
Lazarus Group exploits a Windows zero-day targeting defense and aerospace firms across four countries. Microsoft patches 398 vulnerabilities in August Patch Tuesday. Chrome VPN extensions—737 of them—are routing user traffic through malicious proxies and targeting Russian speakers.
Executive Summary
- North Korean threat actor Lazarus Group is exploiting a newly patched Windows zero-day to deliver a custom backdoor to defense and aerospace organizations in France, Germany, Brazil, and India.
- Microsoft released patches for at least 398 security vulnerabilities during August Patch Tuesday, including flaws in Windows and supported software already under active exploitation.
- A widespread campaign using 737 malicious Chrome VPN extensions is intercepting browser traffic and routing it through attacker-controlled proxies, predominantly targeting Russian-speaking users.
- Adobe patched three critical CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic products.
- The “City-Forum” data-theft campaign is exploiting unauthenticated guest access to Salesforce Experience Cloud and ServiceNow portals using custom tooling to enumerate and exfiltrate data.
Top Threats Today
1. Lazarus Exploits Windows Zero-Day Against Defense and Aerospace Sector
Severity: CRITICAL Affected: Defense
The North Korean threat actor Lazarus Group has been attributed to active exploitation of a Windows zero-day vulnerability to deliver a previously unknown backdoor targeting defense and aerospace companies [1]. The campaign has affected organizations across France, Germany, Brazil, and India [1]. Researchers disclosed the vulnerability to Microsoft after examining the long-running campaign, which exploited the job application process ⚠[2]. Federal agencies have been given two weeks by CISA to patch the flaw [2].
Sources:[1] The Hacker News[2] The Record
Recommended Action
- Defense and aerospace organizations in targeted geographies should immediately apply Microsoft security updates addressing this zero-day.
- Conduct forensic review of job application systems and processes for signs of compromise or unauthorized access.
- Implement network segmentation to isolate critical systems and reduce lateral movement risk from compromised endpoints.
- Enable endpoint detection and response (EDR) to identify unusual system behavior consistent with backdoor activity.
2. Microsoft Patch Tuesday: 398 Vulnerabilities, Some Already Exploited
Severity: HIGH Affected: Technology
Microsoft released patches for at least 398 security vulnerabilities in Windows and supported software during August Patch Tuesday [1]. The update volume continues an escalation trend, with security experts attributing the surge to AI-assisted vulnerability discovery [3]. At least one vulnerability is already being actively exploited in the wild, and two others were publicly detailed prior to the patch release [1]. Security experts emphasize that prioritization should be the main focus given the massive CVE volume [2].
Sources:[1] Krebs on Security[2] Dark Reading[3] The Record
Recommended Action
- Prioritize patching for Windows systems and critical productivity software (Exchange, SharePoint, Dynamics) over optional components.
- Test patches in a non-production environment before enterprise deployment to minimize downtime risk.
- Monitor security bulletins and CISA advisories for actively exploited vulnerabilities requiring expedited remediation.
- Deploy endpoint detection tools to identify exploitation attempts targeting unpatched systems.
3. Malicious Chrome VPN Extensions: 737 Imposters Intercept User Traffic
Severity: HIGH Affected: Technology
More than 737 free VPN and proxy browser extensions published on the Chrome Web Store have been identified as malicious [1][2]. The extensions impersonate legitimate VPN and proxy services while routing users’ traffic through SOCKS5 proxies operated by a single attacker-controlled provider ⚠ [2]. The campaign primarily targets Russian-speaking users seeking access to blocked services, with the goal of intercepting browser traffic [1]. The extensions were published across at least 40 different Chrome Web Store developer accounts [1].
Sources:[1] The Hacker News[2] BleepingComputer
Recommended Action
- Audit Chrome extension inventory across the organization and remove any VPN or proxy extensions not explicitly approved by IT security.
- Disable or restrict installation of extensions from untrusted or newly created developer accounts.
- Use Chrome Enterprise controls to block suspicious extensions and monitor user extension installations.
- Educate users on risks of free VPN extensions and recommend organization-approved VPN solutions only.
4. Adobe Patches Three CVSS 10.0 Vulnerabilities in ColdFusion and Campaign Classic
Severity: HIGH Affected: Technology
Adobe has released patches addressing multiple critical vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic products [1]. The most severe flaws are rated CVSS 10.0 and could result in arbitrary code execution and privilege escalation if successfully exploited [1]. CVE-2026-48362 is among the critical vulnerabilities patched [1].
Sources:[1] The Hacker News
Recommended Action
- Identify all ColdFusion, Commerce, and Campaign Classic instances in the environment and prioritize patching for CVSS 10.0 vulnerabilities.
- Review change logs and access logs for signs of exploitation targeting these products.
- If immediate patching is not possible, implement additional authentication and network access controls around these services.
5. City-Forum Campaign Exploits Salesforce and ServiceNow Guest Portals
Severity: HIGH Affected: Technology
A long-running data-theft campaign dubbed “City-Forum” has been active since at least March 2025 and targets organizations across multiple sectors [2]. The campaign uses custom tooling to exploit unauthenticated guest access to Salesforce Experience Cloud and ServiceNow customer portals [1][3]. Attackers enumerate and exfiltrate sensitive data exposed to anonymous users through these portals [3].
Sources:[1] BleepingComputer[2] Dark Reading[3] SecurityWeek
Recommended Action
- Audit Salesforce Experience Cloud and ServiceNow customer portal configurations to identify any data accessible to unauthenticated guest users.
- Restrict guest portal access to only essential information and enforce authentication where possible.
- Review portal access logs for unusual enumeration activity or large data downloads.
- Implement data loss prevention (DLP) rules to detect exfiltration of sensitive information from these platforms.
Today’s Action Checklist
- ☐ URGENT: If your organization operates in defense/aerospace in France, Germany, Brazil, or India, verify Windows systems are patched against the Lazarus zero-day and review job application infrastructure for compromise indicators.
- ☐ HIGH: Prioritize Microsoft Patch Tuesday deployment for Windows and critical enterprise applications; expedite patches for known actively exploited CVEs.
- ☐ HIGH: Audit Chrome extension inventory organization-wide; remove or block 737 malicious VPN extensions and establish approval policy for future extension installations.
- ☐ HIGH: Patch Adobe ColdFusion, Commerce, and Campaign Classic CVSS 10.0 vulnerabilities; review access logs for exploitation attempts.
- ☐ MEDIUM: Audit Salesforce Experience Cloud and ServiceNow portal guest access; restrict data exposure and monitor for enumeration activity consistent with City-Forum campaign.