The Lazarus Group, a North Korean state-sponsored hacking collective, has been linked to a sophisticated cyber espionage campaign dubbed Operation Dream Job. This campaign leverages a recently patched Windows zero-day vulnerability (CVE-2026-68820) to escalate privileges and deploy a new backdoor named Troy. The group targets defense and aerospace companies in France, Germany, Brazil, and India by impersonating recruiters on platforms like LinkedIn and offering fake job opportunities.

A recent report indicates that the Lazarus Group, a North Korean state-sponsored hacking collective, has been exploiting a Windows zero-day vulnerability to achieve SYSTEM-level access and deploy a new backdoor. This activity is part of a broader cyber espionage campaign known as Operation Dream Job. The campaign specifically targets defense and aerospace companies across several countries.
The reported attack chain begins with social engineering tactics. The Lazarus Group is said to impersonate recruiters on professional networking platforms, such as LinkedIn, to engage with employees of target organizations. These interactions involve offering fake job opportunities, likely as a precursor to delivering malicious payloads or links that initiate the exploitation process.
The core of the attack involves a recently patched Windows zero-day vulnerability, identified as CVE-2026-68820. This vulnerability is leveraged for privilege escalation. In this class of attack, an initial foothold, often gained through user interaction with a malicious file or link, is used to trigger the flaw. The successful exploitation of such a vulnerability allows an attacker to elevate their privileges from a standard user account to SYSTEM, granting them extensive control over the compromised system.
Upon achieving SYSTEM access, the Lazarus Group reportedly deploys a new backdoor, which has been named Troy. Backdoors of this nature typically provide persistent remote access to the compromised system, allowing attackers to execute commands, exfiltrate data, and further entrench themselves within the network. This persistent access is crucial for long-term espionage objectives.
The campaign's focus is specifically on defense and aerospace companies. The reported target countries include France, Germany, Brazil, and India. This targeting aligns with the typical objectives of state-sponsored groups, which often seek intellectual property, strategic information, or technological advantages from critical industries.
Mitigation for this class of attack typically involves a multi-layered approach. Prompt application of security patches, such as the one for CVE-2026-68820, is critical to close known exploitation vectors. Additionally, robust endpoint detection and response (EDR) solutions can help detect and block the deployment of backdoors like Troy. User awareness training is also vital to educate employees about social engineering tactics, particularly those involving impersonation and fake job offers on professional networking sites.
This incident underscores the persistent threat posed by sophisticated state-sponsored actors and their continuous development of new tools and techniques, including the exploitation of zero-day vulnerabilities. The combination of social engineering with technical exploits highlights the need for both robust technical defenses and vigilant human security practices within targeted industries.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed