Lazarus Burns a Windows Zero-Day & 737 VPN Extensions Caught (08/12/2026)
- › Lazarus exploited a newly patched Windows flaw as a zero-day to gain SYSTEM and drop a previously unseen backdoor at defense and aerospace firms.
- › The same operation used post-quantum key exchange to protect delivery of the exploit, which is an attacker adopting cryptography most defenders have not deployed.
- › Researchers found 737 free Chrome VPN and proxy extensions routing browser traffic through proxy infrastructure.
- › Adobe shipped fixes for three CVSS 10.0 flaws across ColdFusion, Commerce, and Campaign Classic.
- › Attackers are exploiting CVE-2026-59310, a 9.8 directory traversal in VMware vCenter, for persistent remote access.
Two items today are about tools that were supposed to be protective. A set of 737 Chrome extensions marketed as VPNs were routing browser traffic through proxy infrastructure, and a researcher published a Defender bypass the day after Patch Tuesday. Above both, Lazarus burned a Windows zero-day on defense and aerospace targets and wrapped the delivery in post-quantum key exchange, which is worth sitting with: the adversary deployed a cryptographic upgrade most of the organizations they target have not started.
Top 5 Critical Security Alerts
1. Lazarus Spends a Windows Zero-Day on Defense and Aerospace
The North Korean group is credited with zero-day exploitation of a newly patched Windows flaw to gain SYSTEM access and deliver a never-before-seen backdoor at defense and aerospace companies. Separate reporting notes the operation used post-quantum key exchange to protect delivery of the exploit itself. The Hacker News
Operator Note: Post-quantum key exchange in a delivery chain is the detail to carry into a budget conversation. The argument for migrating has been that someone may decrypt captured traffic years from now. An adversary using it today to protect their own operation says the technology is mature enough to field, whatever your roadmap says.
2. 737 Chrome Extensions Sold as VPNs Were Routing Your Traffic
Researchers identified 737 free VPN and proxy extensions on the Chrome store intercepting browser traffic and routing it through proxy infrastructure. The set mainly targeted Russian-speaking users looking to reach blocked services. The Hacker News
Operator Note: A browser extension with proxy permissions sees everything the browser sees, including sessions your actual VPN is protecting at the network layer. This is a good week to pull the installed-extension inventory for your managed browsers, which most organizations can do from the console and almost nobody has looked at.
3. Adobe Ships Three Maximum-Severity Flaws at Once
Adobe patched critical vulnerabilities across ColdFusion, Commerce, and Campaign Classic, including three scoring CVSS 10.0, that lead to arbitrary code execution and privilege escalation. The Hacker News
Operator Note: This is the second maximum-severity Campaign Classic flaw in under two weeks. Marketing automation platforms hold the whole customer list and sit outside the patch cadence IT tracks, which we said on August 2 and is still true.
4. A Defender Zero-Day Lands the Day After Patch Tuesday
A researcher published a proof of concept for ShieldBreak, a Microsoft Defender flaw granting SYSTEM privileges, claiming it bypasses the patch shipped in the August update. BleepingComputer
Operator Note: A local privilege escalation in the security product itself is worth more to an intruder than most application flaws, because it is installed everywhere and trusted by everything.
5. VMware vCenter Is Being Exploited for Persistent Access
Attackers are actively exploiting CVE-2026-59310, a directory traversal flaw in Broadcom VMware vCenter scoring 9.8, to establish persistent remote access. The Hacker News
Operator Note: vCenter is the management plane for every virtual machine under it, so this is the same shape as the N-able story: compromise the console and the estate comes with it.
Additional Security Alerts
Threat Intelligence
- Malicious LiteLLM releases sat on PyPI for 40 minutes: Two poisoned releases tied to the Trivy compromise carried credential-stealing code for cloud keys, SSH keys, Kubernetes tokens, and database passwords, with 2,100 organizations potentially exposed. The Hacker News
- Akira blocked the victim’s security tools and then broke its own decryptor: The crew disabled defenses successfully and then could not deliver working recovery. The Register
Vulnerabilities
- Plug and Pwn turns a fake USB device into SYSTEM: The technique abuses Windows device installation to reach full privileges from a plugged-in peripheral. BleepingComputer
- Zoom screen sharing can be used to hijack a device: Researchers found a path from a shared screen to control of the attendee’s machine. Ars Technica
- SAP Commerce Cloud allows unauthenticated code execution: The flaw needs no credentials to reach arbitrary execution. The Hacker News
Security Breaches & Incidents
- Uber Freight is investigating an extortion claim: A crew says it took data from the logistics arm. TechCrunch
- Ransomware hits Colombia’s Justice Ministry days before a presidential transition: The timing puts recovery against a hard political deadline. Dark Reading
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.