View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Lazarus Exploited Windows AFD.sys Zero-Day to Deploy ForestTiger

๐Ÿšจ ACTIVE EXPLOITATION

  • Lazarus Exploited Windows AFD.sys Zero-Day to Deploy ForestTiger Lazarus exploited a Windows zero-day to deploy ForestTiger.

    • Lazarus targeted defense, aerospace, and aviation organizations in Europe, India, Brazil, and elsewhere.
    • Windows AFD.sys contained CVE-2026-68820, a use-after-free flaw enabling SYSTEM-level privilege escalation.
    • Fake job offers delivered encrypted ZIPs containing PDF viewers, malicious libmupdf.dll, and concealed payloads.
    • MISTPEN used Microsoft Graph and OneDrive to retrieve modules before deploying FudModule v3.1, ForestTiger, or Troy.
    • Affected Windows 11 builds included 26100 and 26200; reported SHA-256 IOC: 72dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289. ๐Ÿ“„ Source: gendigital.com ยท ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek
  • Malicious LiteLLM PyPI Releases Potentially Exposed 2,500 Organizations Malicious LiteLLM releases potentially exposed thousands of organizations and CI/CD pipelines.

    • LiteLLM users, AI companies, enterprises, SaaS providers, and cybersecurity vendors were potentially exposed.
    • PyPI versions 1.82.7 and 1.82.8 could steal cloud credentials, repository tokens, SSH keys, Kubernetes tokens, database passwords, and LLM API keys.
    • Attackers compromised the Trivy scanner and used an unpinned CI dependency to publish poisoned LiteLLM releases on March 24, 2026.
    • A malicious Python .pth file executed at interpreter startup and searched environment variables, files, process memory, cloud metadata, and Kubernetes paths.
    • CloudSEK mapped potential exposure to 2,500+ organizations and 434,000 CI/CD pipelines; reported IOCs include SANDCLOCK and GitHub repositories tpcp-docs and docs-tpcp. ๐Ÿ“„ Source: cloudsek.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • ShieldBreak PoC Claims to Bypass Microsoft Defender Fix for SYSTEM Access A researcher released a PoC claiming to bypass Microsoft's Defender fix for RoguePlanet.

    • Microsoft Defender on Windows 11 25H2 and Windows Server 2025 is reportedly affected.
    • ShieldBreak targets the Defender privilege-escalation flaw CVE-2026-50656, known as RoguePlanet.
    • The PoC reportedly exploits Defender file-handling behavior to obtain local SYSTEM privileges.
    • The code includes Warden.dll, Report.wer, and eicar_com.zip; Windows 10 is described as vulnerable but unsupported by the PoC.
    • The claimed bypass and 100% success rate have not been independently verified. ๐Ÿ“„ Source: github.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • ClickFix campaign deploys CNCMachineRMS RAT through signed IBM SPSS IDE A ClickFix campaign is deploying the CNCMachineRMS remote-access trojan.

    • Windows users are targeted through ClickFix by abusing IBM SPSS WinWrap Basic IDE, WinWrapIDE.exe.
    • CNCMachineRMS is a 1.14 MB x64 RAT with shell, file management, screen capture, local-account backdoor, seven persistence methods, and payload execution.
    • The signed IDE loads dropped DLLs through COM; four decoys invoke BabaDeda shellcode via the EnumTimeFormatsEx callback.
    • The RAT has no import table, resolves APIs by hash, builds strings at runtime, and uses an obfuscated HelperStandardizationApplication.bin configuration.
    • C2 indicators include notepadreleased[.]com and 85[.]158.110[.]78 over TCP/443, with 600-second beaconing. ๐Ÿ“„ Source: levelblue.com ยท ๐Ÿ“Ž Coverage: gbhackers.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)
  • Google-Themed 'New Audio MSG' Phishing Campaign Steals Account Credentials A phishing campaign uses fake voicemail emails to steal Google account credentials.

    • Google Workspace and Google Voice users are targeted through work email.
    • The campaign harvests credentials on a fake Google-themed sign-in page.
    • A "Play Audio" link sends recipients through tracking and redirect services before loading the phishing page.
    • The recipient's email address is Base64-encoded in the URL fragment for page personalization.
    • IOCs include sendgrid[.]net, rdnjfgli.r.ap-northeast-1.awstrack[.]me, gm2.drr[.]accoderkubes[.]com/workspace/googlev.html, and spy.mwork801[.]com. ๐Ÿ“„ Source: x.com ยท ๐Ÿ“Ž Coverage: cybersecuritynews.com ยท ๐Ÿ‘ via Cyber Security News, cryptika.com (discovered)

๐Ÿ“‹ ADVISORIES

๐Ÿ”“ CVEs & KEV

  • CVE-2025-41769 โ€” CVSS 9.3 โ€” Unauthenticated Buffer Overflow in PROFINET ServiceThe device's PROFINET serv...
  • CVE-2025-41770 โ€” CVSS 8.7 โ€” Unauthenticated Denial of ServiceAn unauthenticated denial-of-service vulnera...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check