Urgent Threats & Advisories

Active and archived focus items for SOC teams and threat hunters

ACTIVE RIGHT NOW

CRITICALADVISORY20h ago

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Head Mare APT is actively exploiting two vulnerabilities in unpatched TrueConf servers to deploy PhantomCore and PhantomGraph backdoors to conference participants. Affected organizations using TrueConf are at immediate risk of system compromise and privilege escalation. Attackers are replacing legitimate client installers and using OneDrive for command and control.

Action required
Identify and patch all TrueConf servers immediately. Scan for suspicious OneDrive C2 communications and monitor for PhantomCore/PhantomGraph indicators. Check client installer integrity and review conference participant endpoints for signs of compromise.
TrueConf ServerMicrosoft
CRITICALADVISORY20h ago

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Microsoft patched CVE-2026-68820, a zero-day use-after-free in afd.sys kernel driver actively exploited for SYSTEM privilege escalation. This is the fourth afd.sys zero-day since 2022, with historical links to nation-state actors. All Windows systems running unpatched afd.sys are at immediate risk of local privilege escalation.

Action required
Prioritize patching CVE-2026-68820 (afd.sys) on all Windows endpoints. Hunt for exploitation attempts by searching for unexpected afd.sys process interactions, kernel crashes, and lateral movement from standard user accounts to SYSTEM.
afd.sysWindows Sockets APIWindows User Profile ServiceWindows Container Isolation FS Filter DriverWindows DNS server
HIGHADVISORY20h ago

Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

North Korean state-sponsored operatives are actively infiltrating foreign tech companies by applying for legitimate developer roles, likely to establish persistent access for espionage or financial theft. This threat targets any organization hiring remote developers, particularly in crypto, fintech, and high-value tech sectors. If hired, these operatives gain internal network access and can establish command and control infrastructure.

Action required
Implement enhanced vetting for remote developer hires: verify employment history through independent channels, conduct video interviews requiring real-time technical problem solving, monitor new developer accounts for suspicious behavior during onboarding including unusual file access patterns and lateral movement attempts.
Google GeminiChrome Remote DesktopAIApplyFinal Round AI

ARCHIVE

Category:
Severity:
No focus items found.
Try a different filter.