Microsoft patches 398 flaws; SharePoint exploited; Lazarus deploys Windows backdoor
ID: 92b7962c-e048-5d42-9815-35e662cc2a6b
STIX ID: report--92b7962c-e048-5d42-9815-35e662cc2a6b
Feed Name: defend.network
Microsoft released patches for 398 vulnerabilities including an actively exploited SharePoint authentication bypass (CVE-2026-55040, CVSS 9.1); the briefing also reports a Lazarus Group Windows zero-day used to deploy a novel SYSTEM-level backdoor against defense and aerospace organizations across multiple countries, 737 malicious Chrome VPN extensions intercepting browser traffic, and a Mirai-derived Evooo1Bot compromising routers—urgent patching, EDR auditing, extension removal, and router hardening are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
