678,438 Leaked: France Tax Hack Via One Dead VPN Credential

678,438 Leaked: France Tax Hack Via One Dead VPN Credential

TL;DR

  • CVSS 9.8 Apple Screen Sharing RCE + CISA KEV Dump: Authentication Bypass Epidemic Hits Enterprise. Which zero-day is your CISO pretending isn't in your stack right now?
  • 678,438 Identities Leaked β€” France's Tax Meltdown. How many more governments are one expired VPN away from a total identity dump?
  • 3,000+ Networks Gone: StopAndProtect Ransomware Exploits 2,000 WordPress Sites as Malware CDNs via Fake CAPTCHA. Is your WordPress site serving ransomware right now without you knowing?

🎭 CISA KEV Gets Fatter While Your Patch Tuesday Goes Limp

CISA just stuffed 3 fresh exploits into KEV while your Patch Tuesday goes limp β€” CVSS 9.8 unauthenticated Apple Screen Sharing bypass lets attackers walk in, drop XMRig miners, and laugh. That's the equivalent of leaving your front door wide open with a welcome mat that says "root access here." 🎭 Active PoC code is circulating. Federal agencies had 14 days under BOD 26-04. Your org still "evaluating impact." Meanwhile TrueConf servers need no auth on TCP 4307 β€” just code injection and full breakout. Patch management: polite term for whack-a-mole with vendor incompetence, on a budget, while the board asks why RTO keeps slipping. So which CVE is your CISO pretending isn't in your stack today?

Another week, another dumpster fire of CVEs. CISA just stuffed three fresh exploits into their Known Exploited Vulnerabilities catalog, and the collective response from enterprise IT? Mostly a frantic scramble to figure out which of the 47 different vendors they bought stuff from actually owns the affected gear.

πŸ”₯ August Bounty – The Highlights

  • CVE-2026-72530 – TrueConf Server Goes Nuclear – Kaspersky's ICS-CERT dropped this gem August 19th. No authentication needed on TCP port 4307 – just a code injection (CWE-94) that gives attackers arbitrary code execution with full breakout from isolated environments. CVSS 9.5/9.0. Versions 5.3.X through 5.5.5 are Swiss cheese. Patch to 5.3.9, 5.4.9, or 5.5.5 within 48 hours or assume your video conferences are public theater.
  • CVE-2026-65400 – Apple Screen Sharing Goes Rogue – CISA dropped this August 15-18th. CVSS 9.8. Unauthenticated network-side authentication bypass in macOS Screen Sharing – faulty SRP state management lets attackers walk in without credentials. Affects Tahoe (<26.6.1), Sequoia (<15.7.9), and Sonoma (<14.8.9). Dutch NCSC confirmed active exploitation via port 5900: attackers gained root access and deployed XMRig Monero miners. Apple patched on August 6–7, but the pre-auth variant CVE-2026-43760 still gives researchers nightmares. Public PoC code is now circulating. πŸ’Έ
  • CVE-2026-20349 & CVE-2026-20316 – Cisco Firewalls Burning – Cisco PSIRT detected active exploitation on August 11 for CVE-2026-20349 (remote access DoS via device reload loops). CISA added both to KEV by July 30. Federal agencies under BOD 26-04 had until August 14 to patch. Hope you like explaining to your CISO why the VPN gateway kept factory-resetting itself.
  • CVE-2026-16232 & friends – Cisco CVE-2026-20230 (SSRF-based arbitrary file writes in Unified CM WebDialer) and PTC CVE-2026-12569 (RCE in Windchill/FlexPLM) hit KEV on June 26th. Federal agencies had until June 28th under BOD 26-04. You're welcome.

πŸ’₯ VMware – Critical CVEs 9.8-Style

July 29th brought Broadcom emergency patches (VMSA-2026-0006) for CVE-2026-59309 and CVE-2026-59310 – vCenter authentication bypass and RCE pathways. CVSS 9.8 each. CVE-2026-59309 grants unauthenticated admin access via directory traversal; CVE-2026-59310 enables full system takeover through code execution. Also bundled: CVE-2026-47876, a VM escape flaw. "Mandatory firmware rollouts" in your change-request queue means infrastructure teams get to explain yet another weekend outage.

🎯 The Game

Let's be honest about what this signals:

  • Authentication bypass is free cybersecurity bingo – CWE-287 and CWE-94 showing up in Apple Screen Sharing, TrueConf servers, and vCenter proves vendors still can't figure out "verify identity before handing over the keys."
  • Legacy abandonment is accelerating – Apple's patch cycle leaves older macOS releases hanging while attackers pivot between Tahoe, Sequoia, and Sonoma flaws.
  • Federal compliance just got teeth – BOD 26-04 slaps 3-to-60-day mandates on KEV patching. CISA isn't asking anymore. They're telling. And they're tracking.

The real question isn't which vulnerability your team patches first. It's whether your org will admit that "patch management" is just a polite term for "playing whack-a-mole with vendor incompetence, on a budget, while the board asks why the RTO keeps slipping."

Fix your perimeter, kill unnecessary ports (looking at you, TCP 4307 and 5900), and maybe – just maybe – stop buying software that treats authentication as a suggestion rather than a requirement. Or don't. I hear ransomware negotiation skills are trending on LinkedIn. 😏


πŸ₯πŸ’€ France's Tax System Just Leaked 678,000 Identities β€” and It's Exactly as Stupid as It Sounds

678,438 French tax IDs, birth dates, and incomes walked out the door on one expired VPN credential chain πŸ₯πŸ’€ MFA "bypass technique" β€” aka someone forgot to rotate a cert. DGFiP spotted the anomaly June 30. Cut access. Then did nothing for six weeks. Data hit Telegram. ZeroBytes sold it for thousands. Now retirees are untangling identity theft while the budget goes to "new hardware." 2 million+ records. €3,000+ per victim. One bad VPN. You doing the math or should I?

Aug 21, 2026 β€” French authorities finally admitted what anyone with half a brain and a VPN already knew: the ZΓ©robytes duo ate the Federal Tax System alive. 678,438 personal identifiers, gone. Extracted via a compromised internal VPN credential chain β€” with MFA policies that apparently expired like week-old baguettes. ZeroBytes used a stolen identity for lateral movement, and DGFiP cut access on June 30 only after the actor already had the goods. Anomalous traffic detected then? No action for another six weeks. Brilliant. 😏

How It Happened β€” a Masterclass in Negligence

  • June 12, 2026: ZeroBytes exploits a stolen identity and compromised VPN login path to grab the CAD database β€” tax IDs, addresses, birth dates, tax revenues, family quotients. The full identity starter pack.
  • June 18–30, 2026: Second VPN access. They just kept walking in. DGFiP detects anomalous traffic on June 30 and cuts access β€” but the data's already out.
  • August 12–13, 2026: Data surfaces on Telegram. Jameson Lopp publicly confirms 678,438 records stolen. A separate leak of nearly 2 million residential files confirms persistent access despite initial controls.
  • August 14, 2026: DGFiP director confirms dual breaches. Not stops them. Confirms.
  • August 17, 2026: ZeroBytes claims data sales to "two persons for thousands of euros." DGFiP confirms actual extracted records: 252,149 β€” containing data on >2 million people. That's math the press release conveniently left out.

Total count: ~878,000 individuals exposed across two breach events. All from a compromised VPN, a stolen identity, and an MFA policy that laughed itself to death.

The Fallout β€” Spoiler: It's Even Worse Than You Thought

  • Identity theft: Immediate spike in targeted fraud campaigns. Phishing exploits using personal history β€” names, income brackets, family structures β€” hitting inboxes within hours of disclosure.
  • Per-victim cost: Verified €3,000+ per incident in Q3 alone. On 678,438 records, that's over €2 billion in potential exposure. On 2 million profiles? You do the math.
  • Corporate data exposed: Company names and SIREN numbers now weaponized for business-targeted fraud.
  • Wrench attacks: Stolen records include high-income earners (€100k+ annually) β€” enabling physical intimidation tactics. Over 30 such attacks in early 2026 costing $30M+.
  • Elderly victims hit hardest: Welfare recipients, pensioners β€” the people who least need to waste afternoons untangling tax-fraud bureaucracy.
  • Budget response: Reallocate funds for new hardware. Nothing about fixing the gaping authentication holes that caused this. Priorities!

The Real Problem

  • MFA bypass: Enabled large-scale extraction via a compromised VPN credential chain and stolen identity β€” what DGFiP now calls "MFA bypass technique" like that's a feature, not a smoking crater.
  • Detection gap: Anomalous traffic spotted June 30. Access cut. Zero action for six weeks after that. Reactive culture fully deployed.
  • Distraction: France's social-media ban failure conveniently divided attention while ZeroBytes did its thing. Timing? Coincidence? You tell me.
  • AI-accelerated exploit landscape: Zoom's June 2026 Zoomsday vulnerabilities (CVEs 2026-53413, 53415) weaponized in under 48 hours using fewer than 20 AI prompts β€” showing attackers now move faster than any government incident response. The same AI toolkit ZeroBytes likely used? Priceless.

Outlook β€” or: What "We'll Learn From This" Actually Means

  • Short term: More phishing, more wrench attacks, more exhausted retirees yelling at call centers. Criminal infrastructure already growing β€” estimated $30–124M daily monetization capacity from leaked records. The nearly 2 million additional residential files mean fraud campaigns will scale hard.
  • Mid term: Maybe a legislative slap on the wrist. Probably a task force called "Cyber Resilience 2027." Definitely more vendor contracts. ZeroBytes faces up to seven years if caught β€” which translates to "they're already spending the money." CNIL notification triggered, but nobody expects meaningful enforcement.
  • Long term: Urgent need to modernize legacy authentication. Which translates to "we'll fix it in 2029 if there's budget left." Meanwhile, AI-driven vulnerability discovery shrinks exploit timelines from weeks to hours β€” and France's tax authority still can't patch a VPN.

678,438 people. 2 million+ records. €3,000+ each. One expired VPN credential chain. ZeroBytes' own statement: "For the money."

At least they're honest. 🀷


πŸ’€ The CAPTCHA That Deletes Everything: StopAndProtect's August Massacre

2,000+ legit WordPress sites turned into malware CDNs β€” StopAndProtect ransomware served from domains you already trust πŸ’€ SilentEncryptor encrypts with AES-256. SambaUSBWisper auto-spreads to network shares. VBS locker kills your desktop. All from a fake CAPTCHA click. 31,000+ victim screenshots archived. 700+ credential files dumped. WhatsApp contacts monitored. One click on "I'm not a robot" and your business doesn't exist anymore. Disabled PowerShell yet? No? Why the hell not. 🫠

Remember when CAPTCHAs were just annoying images of crosswalks? Good times. On August 19th, cybercriminals weaponized that trust into a global smash-and-grab operation called StopAndProtect β€” and "protect" here means encrypting your files, stealing your data, and laughing while your SMB shares burn.

Check Point Research analyst JaromΓ­r HoΕ™ejΕ‘Γ­ tracked the campaign across US, Indian, and Russian infrastructure β€” 6,000+ unique IPs linked to infections tracked via exposed campaign directories, with 1,852 in the US and 630 each in Russia and India. Russian state-adjacent actors have every incentive: Moscow's June 2026 IP seizure framework against "unfriendly" companies demonstrates how legal theft and digital theft run on the same logic.

The kill chain reads like a dystopian shopping list:

  • Fake "ClickFix" CAPTCHA β†’ PowerShell injection β†’ .NET downloader from exposed PHP endpoints
  • Drops SilentEncryptor ransomware (AES-256 encryption + credential exfiltration β†’ no recovery without decryption key)
  • SambaUSBWisper harvests network shares and USB drives β†’ lateral movement on autopilot
  • VBS locker kills desktop access, displays ransom note β†’ operational paralysis within minutes
  • SimpleChat proxy provides encrypted chat-based C2 β†’ resilient command channel, hard to sinkhole

The carnage, quantified:

  • 2,000+ legitimate WordPress sites repurposed as malware CDNs β€” payloads served from trusted domains, bypassing reputation filters. Internal campaign logs listed every domain, suggesting the operators catalogued their own infrastructure.
  • SilentDataCollector alongside the ransomware β†’ over 700 archived files of stolen credentials and screenshots, plus a separate directory dumping 31,000+ victim screenshots β€” a self-inflicted operational security failure that also confirms scale.
  • WhatsApp integration enables surveillance of victims' contacts and activity logging
  • Automated VB6 utilities let attackers scale management of compromised sites β€” old WordPress installs with SQL injection, auth bypass, and file-upload RCE served as the entry points

Why it actually hurts:

  • File recovery? Gone. Business continuity? Blocked. Credentials? Dumped.
  • SMB propagation means one infected workstation = entire network owned.
  • Trusted WordPress domains as payload sources defeat most URL-scanning defenses.
  • Compromised servers act as C2 hubs, storage dumps, and telemetry collectors β€” the infrastructure is self-contained.

What to do besides cry:

  • Disable PowerShell for non-admins β€” yesterday. Block .NET downloads from browsers.
  • Network segmentation β€” SMB traffic shouldn't be the Wild West.
  • Application allowlisting β€” if it's not signed, it doesn't run.
  • WordPress hygiene β€” patch, audit plugins, change default creds. Every compromised domain starts somewhere dumb.

StopAndProtect isn't clever. It's lazy, effective, and riding on the corpses of neglected WordPress installs. The CAPTCHA asked if you're human. The payload assumed you're not smart enough to say no. 🀷