HeadFlash

Security

North Korean hackers hit Windows zero-day; AI agents breach Taiwan

Lazarus exploits a fresh Windows flaw, AI agents autonomously hit Taiwan agencies, and more in today's security brief.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Microsoft emergency patch closes Windows zero-day exploited by Lazarus Group

Microsoft released an emergency patch on August 11, 2026, for CVE-2026-68820, a privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock. The flaw was exploited as a zero-day by the North Korean Lazarus Group, and successful exploitation grants system privileges without requiring user interaction. The patch arrives as part of Operation Dream Job, a multi-year campaign tracked back to 2022.

Microsoft issues emergency patch as North Korean hackers caught exploiting dangerous flaw →

AI agents autonomously breached Taiwan nuclear agency in four-day campaign

Taiwan’s Ministry of Digital Affairs confirmed that overseas hackers used AI agent tools, including OpenClaw, to conduct autonomous cyberattacks against government agencies from July 1 to July 4. The campaign, described as the first publicly documented near-autonomous AI cyberattack against a sovereign government, involved 12 attack waves across 21 connected systems. Agents cracked 85 government accounts, extracted over 2,500 personnel records, and expanded to target Taiwan’s nuclear safety agency and at least seven energy companies.

Open-Source AI Agents Breach Taiwan Nuclear Agency in Four-Day Autonomous Strike →

Extension Resurrection: Shadow dependencies in IDE packs open supply-chain attack vector

Bloom Security’s research found that legitimate extension packs on the Visual Studio Code Marketplace and Open VSX can reference nonexistent extensions, allowing attackers to claim those namespaces and publish malicious extensions that install automatically through trusted packs. The study identified 677 vulnerable packs on the VS Code Marketplace and 94 on Open VSX, with combined downloads exceeding 500,000. The attack exploits the fact that extension packs do not pin bundled extensions to specific versions, so automatic updates can introduce newly published malicious versions.

Bloom Security’s Extension Resurrection research exposes a blind spot in developer security →

Jewelbug APT runs state espionage and crypto theft from single C2 panel

Symantec researchers identified a Chinese mercenary APT group, tracked as Jewelbug, that conducts both international cyber espionage and cryptocurrency theft. The group manages hundreds of fake cryptocurrency exchanges while compromising government, military, and telecommunications organizations in Asia and the Middle East. Jewelbug uses three custom malware implants, including a browser extension called PDF Viewer that steals cookies, session tokens, and can escape the browser sandbox.

‘Jewelbug’ APT Balances State Espionage & Cryptocurrency Theft →

Fake Chrome update pop-ups traced to compromised browser extensions

Persistent pop-ups urging users to update Chrome are being pushed by compromised browser extensions affecting Chromium-based browsers including Chrome, Brave, and Opera. The scam displays a Critical Update Required message that downloads a suspicious .vbs or .exe script instead of a legitimate update. Traditional antivirus often fails to detect the threat because the browser itself is not infected; instead, an installed extension dynamically fetches malicious scripts from an external server.

PSA: Don’t trust that Chrome update popup — it could be malware →