SharePoint, Windows zero-day exploited; Lazarus backdoor in defense sector
ID: 72f0f712-7dac-5833-8cee-7b17380b979e
STIX ID: report--72f0f712-7dac-5833-8cee-7b17380b979e
Feed Name: defend.network
This briefing reports multiple high-risk incidents: active exploitation of a critical SharePoint authentication-bypass (CVE-2026-55040) following public PoC release, a Lazarus Group campaign leveraging a Windows zero-day to deploy a SYSTEM-level backdoor against defense and aerospace organizations, a mass campaign of 737 malicious Chrome VPN extensions intercepting user traffic, and sizeable data breaches at SafePal and RingCentral; the report includes recommended mitigations and advises verification of sources before operational action.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
