CISA Deadline August 25: Lazarus Zero-Day, AnMed Ransomware, Cl0p Shell

Proactive Security for the AI Era
NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.
North Korea's Lazarus Group exploited a Windows kernel zero-day for five weeks against defense, aerospace, and aviation companies before Microsoft patched it on August 11, and federal agencies now face a CISA remediation deadline of August 25, which is tomorrow.
This week's top cybersecurity threats span four distinct attack surfaces hitting organizations simultaneously. CVE-2026-68820, a use-after-free race condition in the Windows Ancillary Function Driver for WinSock (afd.sys), gave Lazarus Group a reliable path to SYSTEM privileges that they combined with their FudModule 3.1 rootkit to hide all activity from endpoint security tools. AnMed Health, a nonprofit healthcare system serving upstate South Carolina and northeast Georgia, disclosed a weekend ransomware attack that forced more than 30 medical offices and facilities to close and took down email, phone systems, and patient portals. The Cl0p ransomware syndicate claimed on August 19 to have exfiltrated highly sensitive internal datasets from Shell, the multinational energy giant, marking Cl0p's latest large-scale extortion campaign. SynkLoader, a previously unknown malware family, spreads through Microsoft Teams phishing campaigns that present users with a fake Windows lock screen to capture credentials, bypassing email security controls entirely. Researchers confirmed that more than 9,300 AWS access keys exposed in public repositories between 2022 and 2026 remain active and valid.
Each threat demands a specific defensive response in the next 24 hours. This Intel Drop ranks all five by urgency with the exact patch, configuration change, or detection deployment required. If you do only one thing today: apply the August 2026 Patch Tuesday update to every Windows endpoint before the August 25 CISA deadline expires at end of business.
Threat #1: CVE-2026-68820: CISA Deadline Tomorrow for Lazarus Zero-Day
CVE-2026-68820 is a use-after-free vulnerability in afd.sys, the Windows kernel-mode Ancillary Function Driver that manages network socket operations. Lazarus Group exploited the flaw for five weeks against defense, aerospace, and aviation organizations in Europe and India as part of Operation Dream Job before Microsoft patched it on August 11, 2026. Two competing threads race to access socket state without proper synchronization; when timed precisely, the race corrupts freed memory and yields a kernel read/write primitive that produces full SYSTEM-level privileges without any user interaction required.
The exploitation chain begins with a fake job offer delivered via LinkedIn or email, using Operation Dream Job's established social engineering lure targeting defense and aerospace employees. That lure installs a dropper granting Lazarus initial code execution as a standard user. CVE-2026-68820 then elevates that foothold to SYSTEM, enabling deployment of FudModule 3.1, a kernel-mode rootkit that unlinks malicious processes from the Windows active process list, hides malicious drivers, and filters network connections from all monitoring tools. North Korea's Lazarus Group ran this attack chain against defense-sector targets undetected for five weeks because FudModule 3.1 defeats endpoint detection and response tools operating in user space. The full Lazarus FudModule 3.1 attack chain with IOCs and detection guidance is in the dedicated CVE-2026-68820 deep dive.
CISA added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog following the August 11 patch release and set a federal remediation deadline of August 25 under Binding Operational Directive 26-04. Federal civilian executive branch agencies that have not applied the August 2026 cumulative update are out of compliance as of end of business today. Apply the August 2026 cumulative update via the Microsoft Security Update Guide through Windows Update, WSUS, or direct MSU deployment. Prioritize endpoints used by employees in defense, aerospace, manufacturing, or government contracting roles.
Subscribe to unlock Indicators of Compromise
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Threat #2: AnMed Health Ransomware: 30-Plus Medical Offices Forced to Close
AnMed Health, a nonprofit healthcare system operating across upstate South Carolina and northeast Georgia, disclosed a ransomware attack over the weekend that forced the temporary closure of more than 30 medical offices and facilities. The attack disrupted email, phone systems, and patient portal access across the organization, the same operational disruption pattern documented in the Change Healthcare and Ascension Health ransomware incidents of 2024 and 2025.
Ransomware operators target healthcare for compounding reasons: patient care urgency creates payment pressure, mixed operational technology and legacy IT environments extend attacker dwell time before detection, and patient records command premium prices on dark web markets. AnMed operates dozens of physician offices, specialty clinics, and outpatient facilities, giving an attacker broad lateral movement opportunities once inside the network. Patients requiring urgent care during a ransomware-driven outage face real physical risk when clinical systems are unavailable.
No specific threat actor has claimed responsibility as of August 24 or released patient data. The operational disruption pattern without an immediate public data extortion claim is consistent with ransomware families that encrypt first and negotiate second, rather than pure data theft groups like Cl0p.
Defenders in healthcare and other critical sectors should audit backup accessibility today. Confirm backup systems operate on an isolated network segment with no direct path from primary IT infrastructure. Test backup restoration to a clean environment. Verify that out-of-band communication plans are current and that clinical staff have non-digital escalation paths for urgent care decisions. Healthcare ransomware follows a documented playbook: phishing or exposed remote desktop as initial access, flat-network lateral movement to file servers, then encryption. Segment clinical networks from administrative IT as a durable control.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
Threat #3: Cl0p Claims Shell Data Breach: Energy Sector Extortion Continues
The Cl0p ransomware syndicate claimed on August 19, 2026 to have exfiltrated highly sensitive internal datasets from Shell, the multinational oil and energy company operating across more than 70 countries. Cl0p issued the claim without publishing a data sample or a payment countdown, consistent with the group's tactic of asserting a breach before entering the active extortion negotiation phase.
Cl0p is a Russian-speaking ransomware group active since 2020, responsible for mass data exfiltration campaigns exploiting zero-days in Accellion FTA in 2021, GoAnywhere MFT in 2023, MOVEit Transfer in 2023, and PTC Windchill and FlexPLM in 2026. The group specializes in bulk exploitation of file transfer and document sharing platforms used by large enterprises, exfiltrating data without encrypting systems, then threatening public disclosure to extort payment. Our Cl0p Windchill campaign analysis details the group's 2026 exploitation methods and IOCs.
Shell has not publicly confirmed a breach or specified what categories of data may have been accessed. Energy sector organizations hold data across multiple high-value categories: operational technology network schematics, supply chain contracts, drilling and exploration data, financial trading positions, and employee personal records. Any of these represent significant extortion leverage for a group with Cl0p's track record of mass public disclosure.
Organizations in the energy sector should audit file transfer platform logs for large outbound data transfers to unexpected destinations in the past 90 days. Cl0p gains access through vulnerable managed file transfer and secure document sharing infrastructure, not typically through direct network intrusion. Apply all vendor-issued patches to any internet-facing file transfer platform immediately and review the patch history of those systems against Cl0p's known target CVE list.
Threat #4: SynkLoader Teams Phishing: New Malware Steals Credentials via Fake Lock Screen
SynkLoader is a previously unknown malware family disclosed this week, distributed through Microsoft Teams phishing campaigns that present users with a fake Windows lock screen to capture domain credentials. The malware spreads using compromised Microsoft 365 accounts or external Teams guest invitations, bypassing email security controls that most organizations apply stringently to inbound SMTP traffic.
SynkLoader is a credential-stealing malware that overlays a fake Windows lock screen, visually identical to the genuine Windows lock screen, over the user's display to harvest username and password when the user attempts to unlock their computer. Once credentials are captured, SynkLoader exfiltrates them to an attacker-controlled server and accesses the Microsoft Teams local LevelDB database to steal authentication tokens. Those tokens provide full access to the victim's Teams account without requiring the password, enabling the attacker to read message history, access shared files, and continue the phishing campaign from a trusted internal account.
The Teams delivery mechanism exploits a gap many organizations have not closed. Email filtering is mature and widely deployed; Teams external access controls are frequently left at default, allowing any external Microsoft 365 tenant to message internal users. Attackers exploit this by sending phishing messages through compromised external tenant accounts that appear trustworthy inside Teams.
Block Teams external messaging from unmanaged accounts unless your organization has a specific business need. In the Microsoft Teams admin center navigate to Org-wide settings and restrict External access to only known, trusted federated tenants. Enable Windows Defender Credential Guard on workstations to prevent credential theft from user-mode processes. The Sigma rule in the detection section targets unauthorized access to the Teams credential store.
Subscribe to unlock Indicators of Compromise
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Threat #5: 9,300 AWS Access Keys Still Valid After Years of Public Exposure
Security researchers confirmed this week that more than 9,300 Amazon Web Services access keys publicly exposed in code repositories, cloud storage buckets, and other internet-accessible locations between August 2022 and August 2026 remain active and valid. The four-year exposure window means organizations that have never audited their public repositories could have live credentials indexed by search engines, available to any attacker who searches for them.
An AWS access key exposed publicly is a direct path to cloud infrastructure compromise. An attacker with a valid key can enumerate the associated IAM user's permissions, escalate privileges if the key has overly broad rights, exfiltrate data from S3 buckets, spin up compute resources for cryptomining, or create additional IAM users and access keys to establish persistence before the original credential is rotated. Many organizations rotate secrets only when an incident prompts them, leaving keys exposed for the full duration of the leakage window.
AWS provides Git Secrets, Amazon CodeGuru Reviewer secret detection, and IAM Access Analyzer for detecting exposed keys prospectively, but none of these tools retroactively find keys exposed before the tools were adopted. The risk is concentrated in organizations that began using AWS between 2020 and 2023 when key hygiene practices and secrets management tooling were less mature.
Run "aws iam list-access-keys" for every user in your AWS organization and "aws iam get-access-key-last-used" to identify stale or unused keys for immediate rotation or deletion. Scan all public and private repositories with GitHub secret scanning or truffleHog. Enable CloudTrail in all regions and review 90 days of access logs for any key older than 90 days that you have not previously audited.
Detection Rules for Teams Credential Theft and Fake Lock Screen Attacks
No Sigma rule targeting SynkLoader by name exists yet. The malware was disclosed this week, and community rule authors require days to weeks to publish and validate new signatures. Two behavior-based rules cover the core techniques SynkLoader uses: unauthorized access to the Teams authentication token store (Windows Security Event ID 4663 on the LevelDB directory) and PowerShell invoking a credential prompt (which a fake lock screen credential capture implementation uses via the PromptForCredential API).
The Teams object access rule requires Windows Security event logging and Object Access auditing enabled on the Teams local storage directory. Any process other than Teams.exe accessing the path fires the alert. The PowerShell credential prompt rule requires Script Block Logging enabled through Group Policy under Computer Configuration > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Detailed Tracking. Deploy both rules in your SIEM and set to alert. Tune against baseline before enabling blocking.
WAF rules are not applicable to the five threats in this Intel Drop. CVE-2026-68820 is a host-based local privilege escalation with no HTTP request signature for a WAF to intercept. The AnMed ransomware, Cl0p Shell breach, and SynkLoader Teams phishing all operate through host-level or social engineering channels. The individual CVE deep-dive posts for exploits with web-facing attack surfaces carry their own dedicated WAF rule sets.
Subscribe to unlock Sigma Detection Rules
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
Monday Patch Priority List: What to Do Before Tuesday
Rank your remediation by this order today. The first item resolves CVE-2026-68820 and 420 additional August Patch Tuesday CVEs with a single deployment, making it the highest-leverage action on the list.
Subscribe to unlock Remediation & Mitigation steps
Free subscribers unlock full IOC lists, Sigma detection rules, remediation steps, and every daily briefing.
The bottom line
This week's top cybersecurity threats demand action before Tuesday. CVE-2026-68820 carries a CISA federal deadline of August 25; apply the August 2026 Patch Tuesday update to every Windows endpoint today to satisfy it and close 421 CVEs in one deployment. SynkLoader's Teams-based credential theft bypasses email security entirely, requiring Teams external access restrictions and Credential Guard on workstations. Nine thousand three hundred exposed AWS keys and AnMed's ransomware shutdown confirm that cloud misconfiguration and healthcare targeting remain top attacker priorities. The single most time-critical action: patch Windows before the CISA deadline expires at end of business today.
This analysis is generic. create a free account to score threats like this against your own stack.
Frequently asked questions
What is CVE-2026-68820 and why is the CISA patch deadline important?
CVE-2026-68820 is a use-after-free vulnerability in afd.sys, the Windows kernel driver managing network sockets, that allows a locally authenticated attacker to escalate privileges to SYSTEM level. North Korea's Lazarus Group exploited it for five weeks against defense and aerospace firms before Microsoft patched it on August 11, 2026. CISA added it to the Known Exploited Vulnerabilities catalog and set a federal remediation deadline of August 25, 2026, under Binding Operational Directive 26-04. Federal civilian executive branch agencies that miss the deadline face mandatory remediation enforcement actions under BOD 26-04.
How did Lazarus Group exploit CVE-2026-68820 as a zero-day?
Lazarus Group exploited CVE-2026-68820 as part of Operation Dream Job, sending fake LinkedIn and email job offers to defense, aerospace, and aviation employees in Europe and India. When a target opened the lure, a dropper gave Lazarus initial code execution as a standard user. CVE-2026-68820 then elevated that access to SYSTEM, enabling deployment of FudModule 3.1, a kernel-mode rootkit that hides malicious processes, files, and C2 network connections from every endpoint security tool running in user space.
How does SynkLoader steal credentials via Microsoft Teams?
SynkLoader distributes through Microsoft Teams using compromised accounts or external guest invitations that bypass organizational email filters. Once installed, it overlays a fake Windows lock screen that captures the user's credentials when they attempt to unlock their computer. SynkLoader also reads the Teams LevelDB local database to steal authentication tokens, giving the attacker access to the victim's Teams account without requiring the stolen password. Blocking Teams external access from unmanaged tenants and enabling Windows Defender Credential Guard are the primary mitigations.
Which organizations does the AnMed ransomware attack affect?
AnMed Health is a nonprofit healthcare system serving communities in upstate South Carolina and northeast Georgia. The weekend ransomware attack temporarily closed more than 30 medical offices and facilities and disrupted email, phones, and patient portal access. Patients should contact their care providers directly by phone during the outage and expect delays in scheduling and access to medical records. No threat actor has claimed responsibility as of August 24, 2026, and no patient data has been publicly released.
How did Cl0p breach Shell's systems?
Cl0p has not published technical details of the Shell breach as of August 24, 2026. The group claimed exfiltration of highly sensitive internal datasets on August 19. Cl0p's established method in every major 2023 and 2026 campaign has been exploiting zero-days in managed file transfer and document sharing platforms: GoAnywhere MFT, MOVEit Transfer, and PTC Windchill. Organizations using any Cl0p-targeted platform should immediately audit file transfer logs and confirm vendor security patches are current.
What should I do if my AWS access keys were publicly exposed?
Rotate affected keys immediately: run `aws iam create-access-key` to generate replacements, update all services using the old key, then run `aws iam delete-access-key` to remove the exposed credential. Enable AWS CloudTrail in all regions and review the past 90 days of access logs for the exposed key to identify unauthorized activity. Enable IAM Access Analyzer to detect future public exposure. If the exposed key had broad permissions, assume compromise and audit all resources that key could access.
How do I prioritize patches when multiple critical CVEs appear at once?
Apply three criteria in sequence: first, CISA KEV status with a hard deadline takes absolute priority (CVE-2026-68820 deadline is today); second, unauthenticated internet-facing attack surfaces such as pre-auth RCE and auth bypass; third, confirmed active exploitation regardless of deadline. For the August 2026 patch cycle, applying the full Patch Tuesday cumulative update resolves all 421 CVEs simultaneously, which is more effective than selective patching and simplifies compliance reporting.
Are the August 2026 CISA KEV additions linked to the same threat actor?
No. The August 2026 KEV additions cover distinct threat actors and campaigns. CVE-2026-68820 is attributed to North Korea's Lazarus Group. The August 18 batch covering Windows IKE CVE-2026-33824, SharePoint CVE-2026-55040, VMware vCenter CVE-2026-59310, and macOS CVE-2026-65400 involved a mix of state-sponsored and financially motivated actors. CVE-2026-18577 in N-able N-central is attributed to actors targeting MSP management platforms for downstream customer access. Each requires independent remediation despite appearing on the same catalog.
Sources & references
- BleepingComputer: Lazarus hackers exploited Windows zero-day to target defense firms
- CISA: Known Exploited Vulnerabilities Catalog
- SecurityWeek: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
- Tenable: Microsoft's August 2026 Patch Tuesday Addresses CVE-2026-68820
- Help Net Security: Lazarus hackers pair fake job offers with Windows zero-day exploit
- CISA: Adds One Known Exploited Vulnerability to Catalog (August 19, 2026)
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
