Weekly review

ThreatNoir Morning Brief — August 13

2026-08-13Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — August 13, 2026

The threat landscape continues to intensify as multiple critical vulnerabilities and sophisticated attack campaigns emerge across enterprise platforms and mobile devices. Today's security briefing highlights urgent threats targeting e-commerce infrastructure, defense contractors, cloud portals, and financial systems that demand immediate attention from security teams worldwide.

Hackers Exploit Critical Adobe Commerce Flaw to Hijack Customer Accounts

Active exploitation attempts have been detected against a critical vulnerability in Adobe's Commerce and Magento e-commerce platforms that could enable attackers to hijack customer accounts. The vulnerability, tracked as CVE-2026-71362 alongside related flaws CVE-2026-48411 through CVE-2026-48416, represents a significant risk to online retailers and their customer bases. Organizations operating Adobe Commerce or Magento installations should prioritize immediate patching to prevent account takeover incidents.

Source: Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor Lazarus Group has been attributed to exploiting a newly patched Windows zero-day vulnerability, identified as CVE-2026-68820, to deliver a previously unknown backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The campaign, designated Operation Dream Job, represents a sophisticated cyber espionage effort deploying multiple malware tools including ForestTiger, GetInfoPlugin, MISTPEN, OneScreenCapture, PvPlugin, Troy, and an LPE loader. The attack chain leverages fake job offers to gain initial access and escalate privileges to SYSTEM level, enabling persistent backdoor installation on critical infrastructure.

Source: Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

"City-Forum" Data-Theft Attacks Target Salesforce, ServiceNow Portals

An ongoing data theft campaign leveraging custom tools is actively targeting misconfigured Salesforce Experience Cloud and ServiceNow customer portals to steal data exposed to anonymous users. The threat actors, operating under the "City-Forum" designation, have been observed using infrastructure including the domain city-forum.com and IP address 158.220.87.79 to facilitate their data exfiltration operations. Organizations utilizing these cloud platforms should audit their portal configurations to ensure proper access controls and data exposure restrictions are in place.

Source: "City-Forum" data-theft attacks target Salesforce, ServiceNow portals

Android Malware Combo Takes Out Loans and Relays Victims' Credit Cards

A sophisticated Android malware campaign combines the WindRelay NFC relay tool with the SpyNote remote administration tool to steal live credit card data and facilitate fraudulent loan applications. The malware ecosystem also includes variants such as CypherRAT and SpyMax, with command and control infrastructure spanning IP addresses 45.155.204.234, 45.155.205.234, 45.155.206.234, and 45.155.207.234. This coordinated attack enables real-time card data interception and financial fraud, posing significant risk to Android users and financial institutions.

Source: Android malware combo takes out loans and relays victims' credit cards

Security teams should prioritize threat intelligence integration across these incidents, implement compensating controls for unpatched systems, and enhance monitoring for the identified indicators of compromise across their networks and endpoints.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
CVE7
  • High severity incorrect authorization vulnerability in Adobe Commerce.
  • Critical incorrect authorization vulnerability in Adobe Commerce and Magento.
  • High severity stored XSS vulnerability in Adobe Commerce.
  • High severity stored XSS vulnerability in Adobe Commerce.
  • High severity incorrect authorization vulnerability in Adobe Commerce B2B.
  • Medium severity incorrect authorization vulnerability in Adobe Commerce.
  • Low severity incorrect authorization vulnerability in Adobe Commerce.
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
CVE1
  • Windows Ancillary Function Driver for WinSock (AFD.sys) privilege escalation flaw
Malware8
  • LPE loader
    Module for local privilege escalation and decryption
  • OneScreenCapture
    Module for taking screenshots
  • PvPlugin
    Module for collecting host reconnaissance data
  • GetInfoPlugin
    Module for host profiling and data exfiltration
  • libmupdf.dll
    Malicious DLL used in DLL side-loading chain
  • ForestTiger
    Remote access tool deployed after MISTPEN
  • MISTPEN
    Lightweight downloader used in the infection chain
  • Troy
    New backdoor deployed by Lazarus Group
Android malware combo takes out loans and relays victims' credit cards
Malware4
  • WindRelay
    Android NFC relay malware.
  • CypherRAT
    Variant of SpyNote RAT.
  • SpyMax
    Variant of SpyNote RAT.
  • SpyNote
    Remote Administration Tool (RAT) used in conjunction with WindRelay.
IP Address4
  • 45.155.207.234
    Command-and-control IP address identified by Group-IB.
  • 45.155.205.234
    Command-and-control IP address identified by Group-IB.
  • 45.155.204.234
    Command-and-control IP address identified by Group-IB.
  • 45.155.206.234
    Command-and-control IP address identified by Group-IB.