Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-18 and was added to the RWP archive on 2026-09-07.
August Patch Tuesday was Lazarus on AFD.sys — and Storm-1175 was already on N-central
Week of 11–18 August 2026. Microsoft patched an exploited WinSock LPE. Check Point tied it to Dream Job. The same week Storm-1175 was using the N-central auth bypass hours after disclosure.
Executive summary
FACT: Week of 11 August 2026 Patch Tuesday was not a volume story. Microsoft shipped a large August set (public counts vary 394–421 CVEs — treat the exact tally as REPORTED). Three zero-days mattered: CVE-2026-68820 in AFD.sys (WinSock ancillary driver), exploited in the wild; CVE-2026-72971 container isolation tampering and CVE-2026-62832 User Profile Service EoP, both publicly disclosed. Check Point / THN: Lazarus (Dream Job) used 68820 to drop ForestTiger and a new Troy backdoor against defense/aerospace in France, Germany, Brazil, India — fake jobs, trojanized PDF viewers, FudModule rootkit v3.1 in some write-ups. CISA put 68820 on KEV with an 25 August federal deadline, alongside Cisco Secure Firewall ASA/FTD CVE-2026-20349 and Metabase SQLi CVE-2026-72898 (11 August KEV note).
Same week: Microsoft linked Storm-1175 (Medusa-adjacent, now StormEncryptor since 2 August) to CVE-2026-18577 on N-central — auth bypass already on KEV — with AnyDesk/SimpleHelp, Advanced IP Scanner, Mimikatz. Patch N-central 2026.3.1.10 was the then-current advice. SpecterOps: CDP on a live Chrome/Edge process as post-exploit cookie theft when you already have code exec.
ASSESSMENT: Two control planes — the Windows kernel Lazarus wanted, and the RMM Storm-1175 already had.
The week in one assessment
Nation-state LPE on the desktop and crimeware on the MSP console landed in the same seven days. Patch Tuesday without RMM hygiene was half a week.
1. Most important development
CVE-2026-68820 exploited before the patch. Dream Job is not new; AFD.sys as the elevator is.
2. Active exploitation
CONFIRMED 68820 in the wild (Microsoft + CISA KEV).
CONFIRMED N-central 18577 KEV; Storm-1175 use REPORTED by Microsoft TI as Telefónica summarized.
REPORTED Cisco ASA/FTD 20349 on KEV 11 August.
3. Threat actor / campaign activity
Lazarus/Dream Job vs defense industrial base. Storm-1175/Medusa/StormEncryptor vs anyone whose MSP left N-central on the internet. Do not merge them.
4. Vulnerabilities to prioritize
AFD.sys, N-central 2026.3.1.10+, Cisco firewall KEV, VMware notes from the same recap week. WordPress XSS2Shell (pwn.ai) is a separate CMS claim — REPORTED, not this week's enterprise lead.
5. Identity / cloud / enterprise
Entra logging gap CVE-2026-34348 (Microsoft 6.5) and Unit 42's Chrome passkey-secret-from-memory work are post-exploit identity, not the initial door.
6. Ransomware / criminal activity
StormEncryptor via RMM. Akira credential-spray-without-MFA on VPN appeared in 10–14 August roundups. Destroying recovery remains the extortion pattern.
7. Defensive priorities
- August Patch Tuesday, AFD.sys first.
- N-central off WAN + 2026.3.1.10.
- Cisco ASA/FTD KEV.
- Dream Job: recruiting lures into defense orgs.
8. What changed from last week
N-central moved from “KEV exists” to “Storm-1175 timed it in hours.” Lazarus got a patched-this-Tuesday kernel bug.
9. What we are watching next
Whether N-central sprouted more CVEs (it did, in September). Federal 25 August AFD deadline.
10. RWP assessment
Confidence: High on 68820 + KEV. High that RMM was already the crimeware story. This week is why September's fourth N-central hotfix was not a surprise.
Historical intelligence backfill of the week ending 18 August 2026; added 7 September 2026.
Sources
- The Hacker News — Weekly recap VMware, Windows 0-day, Lazarus
- Telefónica Tech — Cybersecurity briefing 8–14 August 2026
- Cybersecurity News — August newsletter Outlook RCE, Cisco, Windows 0-day
- CISA KEV — CVE-2026-68820 Windows AFD.sys (FCEB deadline 25 August 2026)