Security Roundup: Lazarus's Windows Zero-Day, a Critical Metabase SQL Injection, and a Swiss Government SharePoint Breach (Week of August 10, 2026)
Weekly threat intelligence briefing: Lazarus 5-week Windows zero-day, Metabase CVSS 10.0 unauth SQL injection, Cisco firewall crashes, and Swiss BIT breach.
From a five-week kernel zero-day weaponized by North Korea to an unauthenticated CVSS 10.0 SQL injection in Metabase and active attacks on perimeter appliances, the second week of August was one of the most intense threat landscapes of the summer. Here is your structured intelligence briefing.
1. Lazarus Exploited a Windows Kernel Zero-Day (CVE-2026-68820)
North Korea's Lazarus Group spent at least five weeks exploiting a zero-day vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys). The group used the exploit in Operation Dream Job social-engineering campaigns, pairing it with their FudModule rootkit to strip EDR callbacks directly from kernel space before Microsoft released a fix in August's Patch Tuesday.
2. Metabase Unauthenticated SQL Injection Zero-Day (CVE-2026-72898)
A critical CVSS 10.0 SQL injection reachable through the unauthenticated /api/session/reset_password endpoint allowed attackers to compromise at least five organizations' internal databases. With approximately 2,500 Metabase instances exposed to the public internet, self-hosted administrators must patch immediately to 0.63.5.
3. Cisco Discloses Actively Exploited ASA/FTD VPN Crash Flaw (CVE-2026-20349)
Cisco issued an urgent advisory regarding an unauthenticated denial-of-service vulnerability in ASA and FTD devices running AnyConnect SSL VPN or IKEv2 services. Attackers in the wild are actively crashing edge firewalls by sending malformed packet sequences during VPN handshakes.
4. Progress Kemp LoadMaster Root RCE Under Mass Scanning (CVE-2026-8037)
Following a public proof-of-concept release, threat response teams observed widespread scanning for Progress Kemp LoadMaster appliances vulnerable to pre-authentication root command injection. CISA added the flaw to the KEV catalog with an urgent remediation deadline.
5. Switzerland's Federal IT Agency Breached via SharePoint
Switzerland's Federal Office of Information Technology (BIT) suffered a credential compromise affecting roughly 200 user and service accounts after attackers exploited unpatched on-premises SharePoint flaws. The incident underscores the severe risk of patch latency on internet-facing Microsoft collaboration servers.
Sources & Research References
- Windows Kernel Zero-Day: Check Point Research, BleepingComputer, Microsoft Security Advisory.
- Metabase SQL Injection: Wiz Research, Metabase Advisory, GitHub Security Advisory.
- Cisco Firewall Advisory: Cisco PSIRT Security Advisory, BleepingComputer.
- Progress LoadMaster: eSentire Threat Response Unit, CISA KEV Catalog.
- Swiss Federal Breach: BIT Press Release, Swiss National Cyber Security Centre (NCSC/BACS).