Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article reports on Lazarus Group exploiting a Windows zero-day to gain SYSTEM access and deploy a new backdoor called Troy, targeting defense and aerospace companies through fake job offers. The attacks involve trojanized PDF viewers and DLL side-loading to install malware and steal sensitive data.
The FBI warns that hackers are using social engineering, leaked passwords, and spoofed social media sites to breach accounts and steal explicit content. The stolen material is then sold online, targeting individuals for financial gain.
Walmart leverages a 'trusted agent' approach by co-locating red and blue teams to build trust and enhance security. Through collaborative purple teaming exercises, the company breaks down silos and improves overall security posture and incident response.
Security researchers disclosed 'Plug and Pwn' attacks that abuse Windows Plug and Play to trigger installation of vulnerable vendor software, allowing attackers to gain SYSTEM privileges. The attack exploits the trust in automatically installed drivers.
A critical Windows zero-day vulnerability (CVE-2026-68820) was actively exploited by North Korea's Lazarus hacking group to compromise defense-sector entities. The flaw was weaponized as part of Operation Dream Job, demonstrating continued APT focus on geopolitical targets.
ASEC's Week 2 August 2026 review highlights three major cyber incidents: DragonForce ransomware attacked a South Korean online education firm, Qilin ransomware compromised a South Korean motor and robotics manufacturer, and ShinyHunters claimed a data leak from a US digital healthcare company. These events underscore ongoing threats to educational, industrial, and healthcare sectors.