This briefing covers 20 cybersecurity and geopolitics
stories published around Thursday, August 13, 2026,
including activity involving Lazarus, North Korea,
and 8 disclosed vulnerabilities
(CVE-2026-16033, CVE-2026-55040, CVE-2026-59310, CVE-2026-66898 and others).
Each entry links to the original reporting.
North Korea's Lazarus Group exploited a patched Windows zero-day under Operation Dream Job to compromise defense and aerospace targets in France, Germany, Brazil, and India.
North Korean Lazarus hackers weaponized Windows zero-day CVE-2026-68820 to breach defense-sector companies as part of the long-running Operation Dream Job. The exploitation of an unpatched Windows flaw signals continued DPRK investment in high-value zero-days for industrial espionage.
North Korea's Lazarus Group exploited a fresh Windows zero-day to gain full system control and deploy the previously undocumented ForestTiger backdoor against defense companies. The novel implant suggests Lazarus is actively expanding its malware arsenal alongside its zero-day acquisition pipeline.
Russia's dual-use research vessels continue probing NATO undersea infrastructure in the Baltic, Barents, and Arctic, with NATO's defensive posture still lagging a year after initial warnings.
Kyiv and Moscow are exchanging escalating strikes in the Black Sea region while North Korean-supplied missiles are entering active use on the Ukrainian front. North Korea's live-fire integration into the war marks a tangible expansion of the conflict's multilateral character.
A U.S. Navy MH-60 helicopter fired two Hellfire missiles to disable the steering gear of a Panama-flagged cargo ship amid the Iran conflict. The kinetic boarding-denial tactic signals Washington is actively interdicting maritime traffic linked to Iranian logistics.
CISA issued a two-week patch deadline for the Windows vulnerability North Korean hackers exploited via fake job applications against defense targets. The directive signals the flaw is assessed as an active federal network risk, not merely a private-sector concern.
DRAM prices up 50% in one quarter have pushed Apple, Dell, and HP to evaluate memory from CXMT, a firm the Pentagon designates a Chinese military company. Sourcing from a designated entity would embed PRC military-linked silicon in Western consumer and enterprise hardware at scale.
Attackers compromised the Trivy project to poison LiteLLM, distributing infostealing malware to more than 2,500 downstream organizations. The cascade from a security-tooling repo to an AI infrastructure library exposes how deeply interconnected open-source AI and DevSecOps supply chains have become.
An unnamed ransomware operator hit Colombia's Justice Ministry days ahead of a presidential handover, the latest in a pattern of attacks on Latin American government infrastructure. Timing the strike to a transition period maximizes disruption and exploits reduced institutional continuity.
Attackers are actively exploiting CVE-2026-71362, a critical flaw in Adobe Commerce and Magento, to hijack customer accounts across e-commerce deployments. Successful exploitation puts stored payment data, PII, and merchant back-end access in attacker hands at scale.
Tracebit researchers found that embedding adversarial prompt injections alongside AWS secrets caused attacking LLM agents to trigger their own safety guardrails and abort intrusions.
A flaw in acm-search-v2-rhel9's Collector.ImageOverride field lets a hub-cluster admin deploy arbitrary container images across every managed spoke cluster, achieving RCE. Compromise of a single hub now cascades into full remote-code execution across an entire multi-cluster fleet.
Nightmare Eclipse dropped a zero-day exploit called ShieldBreak hours after Microsoft's August 2026 Patch Tuesday, granting SYSTEM-level privileges by defeating Defender. Timing the release to patch day maximizes exposure windows for unpatched enterprise endpoints.
Threat actors are actively exploiting CVE-2026-55040 (CVSS 9.1), a critical SharePoint authentication bypass patched in July 2026, after public PoC release accelerated the weaponization timeline.
CVE-2026-71473 in ACM's search-v2-operator allows a managed-cluster admin to inject arbitrary Helm values, overriding container images and achieving RCE on the spoke. Paired with CVE-2026-71471, the two flaws create a bidirectional image-injection attack surface across Red Hat ACM multi-cluster environments.
CVE-2026-66898 in LXD lets an attacker supply a crafted backup archive with malicious instance names to write arbitrary files as root on the host via path traversal. Any environment exposing LXD backup import to untrusted input is at risk of full host compromise.
CVE-2026-16033 in LXD's image metadata template processing allows a crafted image to escape the instance templates directory and read or write arbitrary files on the host. The flaw is particularly acute in VM/QEMU execution paths, making containerized cloud infrastructure a viable pivot to bare-metal host access.
Hackers weaponized Rapid7's public proof-of-concept for CVE-2026-55040 within hours of its Tuesday release, launching active attacks against Microsoft SharePoint servers. The incident renews debate over responsible disclosure timing when a CVSS 9.1 bug affects ubiquitous enterprise collaboration infrastructure.
Threat actors are actively exploiting CVE-2026-59310 (CVSS 9.8), a directory-traversal flaw in VMware vCenter, to execute arbitrary code and establish persistent remote access, per QUIRSO.