CVE-2026-68820

Published Aug 11, 2026

Last updated 2 months ago

Exploit knownCVSS high 7.0
Windows
Zero-day
WinSock

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-68820 is identified as a "Use after free" vulnerability found within the Windows Ancillary Function Driver for WinSock. This flaw enables an authorized attacker to achieve local privilege escalation. The vulnerability was recognized as a zero-day exploit and was actively leveraged in attacks. Microsoft addressed CVE-2026-68820 as part of its August 2026 Patch Tuesday release.

Description
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
7
Impact score
5.9
Exploitability score
1
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Exploit added on
Aug 11, 2026
Exploit action due
Aug 25, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-416

Social media

Hype score
Not currently trending
  1. Active in-the-wild zero-day and privilege escalation attacks targeting the Windows kernel and core OS execution layer center on several key vulnerabilities added to CISA's Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-68820 (Windows Kernel Ancillary Function Driver

    @reach2ratan

    12 Sept 2026

    840 Impressions

    19 Retweets

    23 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  2. Check Point Research just detailed how Lazarus Group exploited a Windows zero-day (CVE-2026-68820) in AFD.sys. They lured defense professionals with fake job offers on LinkedIn. https://t.co/ED8UCF4kxu

    @jorgeCISO

    2 Sept 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 🚨 Patch Now | September 1, 2026 Bringing these critical vulnerabilities to your attention: 🔴 Citrix NetScaler ADC/Gateway(CVE-2026-8452, CVSS 8.8) 🟠 Microsoft Windows AFD.sys (CVE-2026-68820, CVSS 7.0) 🔴 PaperCut NG/MF (CVE-2026-81578 & CVE-2026-82078, CVSS 8.

    @CERT_UG

    1 Sept 2026

    115 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Recent zero-days: WinSock AFD.sys (CVE-2026-68820) actively exploited, Defender (CVE-2026-69414) unpatched EoP. NatJack attacks hijack TCP/DNS. Data privacy/integrity severely impacted. (Aug 2026) #Cybersecurity #Vulnerabilities #News

    @YourAnon_irc

    1 Sept 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CVE-2026-68820 | Windows AFD.sys (WinSock) | use-after-free EoP | CVSS 7.0 | ITW local LPE to SYSTEM. Lazarus used it in Operation Dream Job to drop FudModule. on CISA KEV. https://t.co/1Sa6SajI6W #CVE #Windows #ExploitDev

    @_MrNiko

    31 Aug 2026

    138 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 Patch Now | August 25, 2026 Bringing these vulnerabilities to your attention. Today is the CISA deadline for ShieldBreak (CVE-2026-68820). - Dahua cameras Vulnerability - Progress LoadMaster (CVE-2026-8037) https://t.co/fR71dypdSf | #CyberSafeUG #CERTUGCC https://t.co/QP

    @CERT_UG

    25 Aug 2026

    65 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 【技術解説】afd.sysゼロデイ CVE-2026-68820(CISA適用期限8/25=明日) 8月Patch

    @iss_kk_official

    23 Aug 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Lazarus Group Exploits Windows WinSock Zero-Day CVE-2026-68820 to Deploy Advanced FudModule Rootkit | Encrygma — AI Cyber Security Intelligence ⚠️ https://t.co/LhQnDO2YHT

    @crygma

    23 Aug 2026

    72 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2026-68820 is actively exploited and affects the Windows AFD driver. • Privilege escalation • CISA KEV listed 👉 Partner with Digital Warfare today and discover why organizations trust us to identify vulnerable systems. Read more: https://t.co/IBFidsSC2f https://t.co/rn

    @Digital_Warfare

    23 Aug 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. 【実務者への注意喚起】パッチ公開から72時間 ― 「後で当てる」がもう通用しない現実 8月Patch Tuesdayは421件のCVE、うちWinSock(AFD)の使用後解放 CVE-2026-68820 がゼロデイ悪用中でSYSTEM昇格に利用。SAP Commerce

    @iss_kk_official

    23 Aug 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. This week’s defense ticket: prove version + exposure status for Windows CVE-2026-68820, Cisco ASA/FTD CVE-2026-20349, and Zoom’s annotation fixes. Close with evidence and exception owners, not “in progress.”

    @InfosecDotWatch

    22 Aug 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Still sorting through Patch Tuesday? A few vulnerabilities deserve a closer look. In his August Patch Tuesday coverage for Infosecurity Magazine, Phil Muncaster looks at some of the vulnerabilities that stood out this month. Mike Walters highlights CVE-2026-68820 as a priority

    @Action1corp

    18 Aug 2026

    89 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Microsoft'un Ağustos Yaması Final Raporunda 421 Açık ve İki Ek Sıfır Gün Ortaya Çıktı Daha önce duyurduğumuz Microsoft Ağustos yamasının resmi final raporunda toplam açık sayısı 398'den 421'e yükseldi ve Lazarus'un istismar ettiği CVE-2026-68820'nin yanınd

    @BTHaberler

    17 Aug 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. North Korea used servers vulnerable to a bug we found as C2 in its latest campaign targeting the defence, aerospace, and aviation sectors. Check Point's report last week: Lazarus exploited a Windows kernel zero-day, CVE-2026-68820 in afd.sys, since at least early July against ht

    @FearsOff

    17 Aug 2026

    386 Impressions

    3 Retweets

    8 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  15. NOOR Threat Feed Brief Here is a summary of the CVEs in under 120 words, prioritized by real-world exploitation risk: **High-Risk:** 1. **CVE-2026-68820**: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability (local privilege escalation, high

    @noorchronicle

    17 Aug 2026

    5 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Microsoft just dropped patches for 421 CVEs 💀 And one of them was already being exploited as a zero-day. CVE-2026-68820 is a Windows kernel bug that can give attackers SYSTEM privileges. Patch Tuesday is getting scary af. https://t.co/4xHu5AVlc3

    @r3fang

    16 Aug 2026

    1 Impression

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  17. Microsoft’s August Patch Tuesday addressed over 400 vulnerabilities, including one actively exploited zero-day (CVE-2026-68820) in the Windows Ancillary Function Driver. Prioritize systems exposed to privilege escalation risks.

    @Lumideezy

    16 Aug 2026

    90 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  18. 【今月のMSアップデート解説】 8月のセキュリティ更新は今月も420件超と多め ・WinSock AFDの権限昇格(CVE-2026-68820)は悪用確認あり ・SharePoint等のRCEチェーン(CVE-2026-63520)も要注意 昨今、不正アクセスが増え

    @shunyat1031

    16 Aug 2026

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 【緊急】CVE-2026-68820 MicrosoftのWindows Ancillary Function Driver for WinSockに深刻な脆弱性|即時対応が必要 https://t.co/OGjk5HJYtK #IT #Security #cybersecurity

    @Teeeda_worker

    16 Aug 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CVE-2026-68820: Windows WinSock (afd.sys) UAF Mitigation by UBITQUITY. This repository contains a conceptual patch demonstrating the mitigation for CVE-2026-68820, a critical Use-After-Free (UAF) vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys).

    @ubitquity_io

    15 Aug 2026

    144 Impressions

    2 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. ShieldBreak apunta a CVE-2026-50656 y lo que deja claro es bastante incómodo: Microsoft Defender parcheado, máquina parcheada, y aun así terminás en SYSTEM. Y no es una rareza aislada. Lazarus ya viene usando CVE-2026-68820 para subir privilegios en Windows, con casos en Bra

    @FedeJoelH

    15 Aug 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🚨 CVE-of-the-Day: CVE-2026-68820 — Windows AFD.sys, local privilege escalation CVSS: 7.0 | EPSS: N/A (too new to be scored) A use-after-free in a core Windows kernel driver lets an attacker with an existing foothold win a race condition and escalate to SYSTEM. Exploited as

    @YourDailyCVE

    15 Aug 2026

    13 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  23. 🚨 NUEVA CVE: CVE-2026-68820 — Windows WinSock AFD (Use-After-Free LPE) ⚠️ CVSS 7.0 (CRÍTICO) · KEV 11/08/2026 · explotación activa Afectados: Sistemas Windows com driver AFD.sys Use-after-free https://t.co/rkgrmP2emR

    @Douglas01284182

    13 Aug 2026

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 🚨 NOVA CVE: CVE-2026-68820 — Windows WinSock AFD (Use-After-Free LPE) ⚠️ CVSS 7.0 (CRÍTICO) · KEV 11/08/2026 · exploração ativa Afetados: Sistemas Windows com driver AFD.sys Use-after-free no W https://t.co/jmt6RHDBtT

    @Douglas01284182

    13 Aug 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 NEW CVE: CVE-2026-68820 — Windows WinSock AFD (Use-After-Free LPE) ⚠️ CVSS 7.0 (CRITICAL) · KEV 11/08/2026 · active exploitation Affected: Sistemas Windows com driver AFD.sys Use-after-free n https://t.co/HS0KUGrIZY

    @Douglas01284182

    13 Aug 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. "Microsoft patched CVE-2026-68820 as part of August Patch Tuesday, a high severity bug in the Windows Ancillary Function Driver for WinSock already exploited in the wild. The flaw affects Windows 10 1607 to 22H2, Windows 11 23H2 to 26H1, and Windows Server 2012 to 2025, scored ht

    @GHHILL1911

    13 Aug 2026

    242 Impressions

    1 Retweet

    6 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  27. 🚨 Last 24h is HOT — primary sources only CISA added 3 KEVs on 11 Aug (all actively exploited): • CVE-2026-20349 — Cisco ASA/FTD unauth SSL VPN DoS Official: https://t.co/InN3hhGaSD Fed deadline: 14 Aug. No workarounds. Hotfix now. • CVE-2026-68820 — Windows afd.sys L

    @seoscottsdale

    13 Aug 2026

    223 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  28. Lazarus is burning a Windows zero-day (CVE-2026-68820) against defense firms while SharePoint (CVE-2026-55040) falls to public PoC exploitation. #CyberSecurity #BlueTeam #ZeroDay https://t.co/1Fsc4x2SHo

    @itsalreadywhen

    13 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  29. 1/4 🚨 Last 24h cyber snapshot is HOT CISA just dropped 3 KEVs (Aug 11): Cisco ASA/FTD DoS (CVE-2026-20349), Windows AFD.sys LPE (CVE-2026-68820), Metabase unauth SQLi (CVE-2026-72898). Lazarus already weaponizing the Windows zero-day vs defense firms.

    @CipherWardenAI

    13 Aug 2026

    202 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    2 Replies

    1 Quote

  30. North Korean 🇰🇵 Lazarus Group weaponized a Windows zero-day (CVE-2026-68820) in Operation Dream Job, hitting defense and aerospace professionals in France 🇫🇷, Germany 🇩🇪, Brazil 🇧🇷, and India 🇮🇳 with fake Lockheed Martin job offers. - CVE-2026-68820

    @DFIR_Radar

    13 Aug 2026

    199 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  31. Microsoft's August 2026 Patch Tuesday closed 3 zero-days (400+ CVEs total): - CVE-2026-68820 — AFD.sys (WinSock) — actively exploited - CVE-2026-62832 — Windows User Profile Service — publicly disclosed - CVE-2026-72971 — Container Isolation FS Filter Driver — public

    @tac0tech

    13 Aug 2026

    77 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  32. Microsoft patched CVE-2026-68820 as part of August Patch Tuesday, a high severity bug in the Windows Ancillary Function Driver for WinSock already exploited in the wild. The flaw affects Windows 10 1607 to 22H2, Windows 11 23H2 to 26H1, and Windows Server 2012 to 2025, scored

    @NeowinFeed

    13 Aug 2026

    934 Impressions

    3 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  33. North Korea 🇰🇵's Lazarus group deployed a Windows kernel zero-day via a post-quantum encrypted channel against defense and aerospace firms in France 🇫🇷, Germany 🇩🇪, Brazil 🇧🇷, and India 🇮🇳, with a patch shipping August 11. - CVE-2026-68820 is a use-

    @DFIR_Radar

    12 Aug 2026

    228 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  34. Active exploitation of VMware vCenter (CVE-2026-59310) and Cisco ASA/FTD (CVE-2026-20349), plus a Windows afd.sys zero-day (CVE-2026-68820) in this month's Patch Tuesday. #CyberSecurity #BlueTeam #ZeroDay https://t.co/8JN5RsqS06

    @itsalreadywhen

    12 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  35. 🛡️We added Cisco Secure Firewall vulnerability CVE-2026-20349, Microsoft Windows vulnerability CVE-2026-68820 & Metabase vulnerability CVE-2026-72898 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cyberse

    @CISACyber

    12 Aug 2026

    8537 Impressions

    7 Retweets

    18 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  36. Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820): Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and… https://t.co/DBkKoaPWYg

    @shah_sheikh

    12 Aug 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. 🔥 CyberForge CVE of the Day #022 🚨 CVE-2026-68820 — An actively exploited Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free allows a low-privileged local attacker to elevate privileges through kernel memory corruption. ⭐ Vendor: Microsoft ⭐ Comp

    @lee1981b

    12 Aug 2026

    109 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  38. 🔥 CyberForge CVE of the Day #022 🚨 CVE-2026-68820 — An actively exploited Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free allows a low-privileged local attacker to elevate privileges through kernel memory corruption. ⭐ Vendor: Microsoft ⭐ Comp

    @lee1981b

    12 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  39. 🔥 CyberForge CVE of the Day #022 🚨 CVE-2026-68820 — An actively exploited Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free allows a low-privileged local attacker to elevate privileges through kernel memory corruption. ⭐ Vendor: Microsoft ⭐ Comp

    @lee1981b

    12 Aug 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  40. Operation Dream Job #Lazarus exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit. https://t.co/A7xGb08NtE Lazarus also used CVE-2025-49113 to exploit vulnerable Roundcube

    @blackorbird

    12 Aug 2026

    2126 Impressions

    6 Retweets

    19 Likes

    5 Bookmarks

    1 Reply

    0 Quotes

  41. 北朝鮮系Lazarusが、偽の求人を使うOperation Dream Jobを再展開し、WindowsのゼロデイCVE-2026-68820を悪用して防衛・航空宇宙企業を侵害した。攻撃ではトロイ化PDFビューアや新型バックドア、カーネルルートキットも

    @yousukezan

    12 Aug 2026

    2479 Impressions

    0 Retweets

    13 Likes

    10 Bookmarks

    0 Replies

    0 Quotes

  42. 🚨 Microsoft August Patch Tuesday — 398+ CVEs, 3 Zero-Days CVE-2026-68820 — WinSock EoP (ACTIVE zero-day, Lazarus) CVE-2026-62878 — DNS Server RCE (9.8, wormable) CVE-2026-62893 — TFTP Server RCE (9.8, more likely) → https://t.co/vOC4TItXgB #cybersecurity #PatchTuesd

    @ThreatAft

    12 Aug 2026

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  43. Microsoft’s August Patch Tuesday addresses multiple critical vulnerabilities. Prioritise actively exploited CVE-2026-68820, alongside publicly disclosed CVE-2026-62832 and CVE-2026-72971. Review, test and patch promptly: https://t.co/01elXNUXLy #PatchTuesday #MSSP #SOC

    @FactoryInternet

    11 Aug 2026

    190 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  44. 🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗔𝘂𝗴𝘂𝘀𝘁 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 August Patch Tuesday is here, and we have 𝟯 𝗻𝗲𝘄 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀 and 𝟲 vulnerabilities with a CVS

    @horizon_secured

    11 Aug 2026

    314 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  45. Microsoft's August Patch Tuesday fixed 400 flaws, including 3 Windows zero-days, all local privilege-escalation bugs needing no user interaction: • CVE-2026-68820: AFD.sys WinSock flaw, already exploited by Lazarus to deploy the FudModule rootkit • CVE-2026-62832: User Profi

    @XavierRiveraX

    11 Aug 2026

    92 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  46. 0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://t.co/GDI2Z

    @_CPResearch_

    11 Aug 2026

    8491 Impressions

    50 Retweets

    172 Likes

    69 Bookmarks

    2 Replies

    2 Quotes

  47. 0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (#CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://t.co/GDI2

    @_CPResearch_

    11 Aug 2026

    269 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  48. 0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (#CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://t.co/GDI2Z

    @_CPResearch_

    11 Aug 2026

    265 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  49. 0-Day Used by Lazarus in the #DreamJob Campaign Against Defense Sector: 💥LPE via a vulnerability in Microsoft’s Afd.sys driver (#CVE-2026-68820) 🧰New tools, including the #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure https://t.co/GDI

    @_CPResearch_

    11 Aug 2026

    381 Impressions

    1 Retweet

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations