Weekly Threat Intelligence Briefing — Monday, August 31, 2026

Weekly Threat Intelligence Briefing — August 31, 2026

August 31, 2026

Weekly Threat Intelligence Briefing · Monday, August 31, 2026

Coverage window: August 10–31, 2026


A Windows kernel zero-day spent five weeks inside defense firms before Microsoft patched it. Two hundred sixty-seven Zimbra servers fell to a flaw that had a fix in July. And CISA issued three-day and fourteen-day remediation deadlines on the same day, from the same catalog.

The theme this week is the distance between “patch available” and “patch applied.”

CVE-2026-68820 — Windows afd.​sys zero-day, exploited by Lazarus

A use-after-free race condition in the Ancillary Function Driver for WinSock, CVSS 7.0, escalating to SYSTEM. Check Point Research found it in active use in Operation Dream Job: tailored fake job offers aimed at defense, aerospace and aviation firms in France, Germany, India and Brazil, with stated interest in surveillance sensors, drones and robotics. Exploited since early July; patched August 11. The chain deploys the FudModule kernel rootkit — which disables EDR telemetry and tampers with Smart App Control — followed by the Troy backdoor.

DIB implication: the recruiter email is the entry point and your EDR is the target, not the obstacle. If your SSP cites endpoint detection as a control, this campaign was built to switch it off. Five weeks of pre-patch exploitation means patching is not the same as clearing — hunt backward.

CVE-2026-73570 — Zimbra SNMP command injection

CVSS 8.9, unauthenticated remote code execution as the zimbra user. Fixed in ZCS 10.1.20 on July 20. CERT Polska flagged exploitation the week of August 20; Shadowserver counted 155 compromised instances on August 20 and 267 by August 24. Roughly 8,200 instances remain unpatched. KEV-listed August 21, due August 24 — that window has closed.

DIB implication: this is the second Zimbra exploitation event in five weeks, and Zimbra concentrates at smaller subcontractors and municipal bodies rather than primes. That is your supplier base, not your enterprise.

Also KEV-listed: CVE-2026-21962 — Oracle HTTP Server and the WebLogic Server Proxy Plug-in, CVSS 10.0, unauthenticated over HTTP. Oracle patched it in January. Exploitation is confirmed by GreyNoise, CloudSEK and SOCRadar, reported as China-linked across 100-plus countries, chained with older WebLogic flaws and delivering the SNOWLIGHT downloader. And joint advisory AA26-222A on Gunra ransomware (August 10) carries a DC3 co-seal — its named initial-access vectors are FortiOS/FortiProxy appliances.

Watch — the water and wastewater PLC campaign. More than 30 Minnesota systems on July 26–27, nine Michigan systems by August 1, at least seven states. Attackers changed PLC IP addresses and passwords to lock operators out of their own control systems, and left modified project files with ladder-logic discrepancies. Attribution is unresolved: neither the FBI nor Minnesota IT Services has confirmed the Iranian link, and two pro-Russian groups have claimed related access.

Practitioner takeaway

Confirm CVE-2026-68820 is deployed fleet-wide, then hunt backward five weeks — look for EDR telemetry gaps and Smart App Control tampering. Inventory Zimbra across your suppliers, not just your own estate, and treat any internet-facing ZCS below 10.1.20 as potentially compromised rather than merely unpatched. If you run Oracle HTTP Server or the WebLogic Proxy Plug-in, the January CPU is now a KEV item. Maritime operators: the MTS Cyber Plan deadline is about ten and a half months out.

And rebuild your patch SLA around per-entry KEV deadlines. CISA issued three days for current flaws and fourteen for legacy debt on the same day. Under BOD 26-04 the deadline is scored per entry — there is no cycle left to plan around.

PSYber360: Gunra, Lazarus and ShinyHunters records are staged this week. The water-sector cluster is entered as unattributed — the resemblance to the Iranian campaign is similarity, not evidence.

Where does Zimbra sit in your supplier inventory — and did you know that before this week?

Back to Blog