French Breach Claims Rise as Lazarus Exploits Zero-Day
Summary
Pressure is splitting between repeatable access against smaller organizations and high-end exploitation against enterprise platforms. The overlap matters operationally: noisy underground listings can obscure the same identity, patching, and browser-extension weaknesses that advanced campaigns exploit more quietly. Defensive triage should pair rapid external-exposure review with internal authentication and endpoint telemetry.
Today's developments
France carried the largest cluster of forum claims. Sophia claims alleged breaches of CREDEF, Minute Sports, Atlantic Cafe, Ligne Sud, Mister Expo, SMPGA, Vitacology, and several other French organizations; Sophia01 separately claims Better Human Cie and For Interieur in France, plus Branch in the United States. The claims remain unverified, but their repetition across education, retail, sports, publishing, and local services points to a reusable access method or a common pool of exposed credentials rather than a single sector-specific campaign.
Other named operators broadened the victim set. PrimeVendor claims alleged breaches of Perle Finance in France and IN SPORT and Monava Trasporti Internazionali in Italy. ZeroBytes claims the French public-finance directorate DGFiP and the Agency for French Education Abroad. The handle ./DanzNismXst7 claims the Indonesian National Police, exfilar claims the UN Food and Agriculture Organization, and bytetobreach claims the Bulgarian Army. In the commercial sector, jetset claims PagesJaunes SA, SUB-ZER0 claims Benetton Group, and Petro_Escobar claims Net2phone. Market Exchange, Laciey, and several other sellers also posted alleged financial, customer, or cryptocurrency-sector data listings across multiple countries; these listings are claims only and their contents have not been independently verified.
Security reporting describes a simultaneous rise in platform exploitation. Researchers attribute a Windows zero-day campaign to Lazarus, saying the flaw enabled SYSTEM-level access and backdoor deployment; CISA then gave US federal agencies two weeks to patch the exploited Microsoft bug. A SharePoint vulnerability was reportedly attacked shortly after proof-of-concept code appeared. The City-Forum campaign used unauthenticated guest access in Salesforce and ServiceNow with a custom toolset, while researchers identified 737 Chrome VPN extensions routing user traffic through proxy infrastructure.
Two incident reports reinforce the detection problem. Three intrusions at the UK criminal-records office reportedly remained undetected for two years, showing how long unauthorized access can persist when identity and audit signals are weak. Ceva Logistics also reported operational disruption from a cyberattack. Separately, the FBI warned that social engineering is being used to compromise accounts and steal explicit content, and WhatsApp introduced a new scam-alert feature aimed at suspicious contact patterns.
Threat landscape signals
France accounted for 37 of 231 tracked events, about 16 percent, followed by the United States with 29. The five most active handles generated 63 events, or roughly 27 percent of the total, although much of that volume came from defacement and other high-frequency activity rather than confirmed compromise. Government administration was the largest victim-industry label with 15 events; IT services, education, wholesale, health care, and financial services also appeared repeatedly.
Defacement led the category count at 49, while ransomware remained high at 36 and initial-access listings at 32. The combination matters more than any single count: readily traded access can feed later ransomware or data-theft operations, and newly published exploit code can compress the time available to patch exposed systems. Teams should prioritize the Microsoft and SharePoint fixes identified in active exploitation, review Salesforce and ServiceNow guest access, inventory browser extensions, and hunt for anomalous authentication followed by privilege escalation or new persistence.