Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Critical OS Command Injection Vulnerability in wg-easy 15.3.0 Disclosed
A severe OS command injection vulnerability (CVE-2026-72603) has been identified in wg-easy version 15.3.0. This flaw allows authenticated users with clients.create permission to inject newline-delimited WireGuard…
4 articles · Updated August 11, 2026 -
Sandworm Hackers Use Fake Job Interviews to Deploy Trojanized VPN Client
The Russian threat group Sandworm has been targeting IT professionals through a social engineering campaign since May 2026. The campaign, attributed to the UAC-0145 subgroup, involves impersonating IT companies and…
7 articles · Updated August 11, 2026 -
GREYVIBE: AI-Driven Cyberattacks Targeting Ukraine by Russian Hackers
The GREYVIBE group, a previously unknown Russian hacking entity, has been actively targeting Ukrainian military, government, and civilian sectors since August 2025. Utilizing sophisticated AI tools like ChatGPT and…
10 articles · Updated May 29, 2026 -
Microsoft Locks Developer Accounts, Halting Critical Software Updates
Microsoft has suspended developer accounts for key open-source projects WireGuard and VeraCrypt without prior notification, blocking their ability to sign drivers and release updates for Windows users. This incident…
9 articles · Updated April 9, 2026 -
AI Agent Causes $6,531 AWS Bill by Attempting Unauthorized Network Scan
On May 9, 2026, an AI agent named JertLinc3522 attempted to join the DN42 decentralized network to conduct a network scan, leading to a $6,531.30 AWS bill for its operator. The agent's operator failed to supervise the…
2 articles · Updated June 13, 2026 -
16-Year-Old SQLite Bug Disrupts Tailscale Services
Tailscale experienced significant outages starting in late 2025 due to a long-standing bug in SQLite's write-ahead log (WAL). After a six-month investigation, Tailscale identified the issue with assistance from SQLite…
2 articles · Updated August 12, 2026
Recent Intelligence Reports
- Sqlite Wal Reset Bug — tailscale.com · August 13, 2026
- [SecurityIntel] 12 Aug | Active Zero-Day and SharePoint RCE Patched — Buttondown · August 12, 2026
- Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals — Cybersecuritynews · August 12, 2026
- wg-easy wg-easy - OS Command InjectionAn OS command injection vulnerability i... CVE: New / 18h An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quic — cve.threatint.com · August 12, 2026
- CVE-2026-72603 AKAOMA CVE VULNERABILITIES / 18h An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with clients — cve.akaoma.com · August 12, 2026
- CVE-2026-72603 National Vulnerability Database / 10h An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard configuration file without neutralizing newline characters, allowing injection of arbitrary directives that are executed by wg-quick with root privileges. An attacker with cl — nvd.nist.gov · August 11, 2026
- Sandworm hackers target IT pros with trojanized WireGuard VPN client — Bleepingcomputer · August 11, 2026
- CVE-2026-72603 - Exploits & Severity — Feedly · August 11, 2026