Threat Brief — 2026-08-24 — New RCE in VS Code, DPRK tradecraft exposed
Two fresh Microsoft CVEs headline today: a remote code execution flaw in the VS Code MSSQL extension and a privilege escalation bug in the Desktop Window Manager. Meanwhile, a tradecraft analysis of North Korean threat actors reveals they're leaning on native Windows tooling rather than custom rootkits to escalate privileges and evade defences. A new Russian decree authorising transfer of critical-infrastructure assets to temporary management for owners who fail to protect facilities signals escalating regulatory consequences for OT security failures.
Top items
- CVE-2026-47292 — VS Code MSSQL Extension RCE. A remote code execution vulnerability in the Visual Studio Code MSSQL extension. RCE in a widely used dev-tool extension is high-risk for any shop where developers connect to SQL databases from VS Code; patch the extension immediately. (src: MSRC)
- CVE-2026-65787 — Desktop Window Manager Elevation of Privilege. A privilege-escalation flaw in the Windows Desktop Window Manager. MSRC updated the acknowledgement (informational change only), but the underlying EoP risk remains relevant for hardening guidance on endpoint workstations. (src: MSRC)
- DPRK actors leverage native Windows tasks and legit software for stealthy privilege escalation. New analysis shows North Korean hackers are abandoning complex rootkits in favour of living-off-the-land techniques using built-in Windows scheduled tasks and legitimate signed binaries to gain maximum privileges and bypass endpoint protections. Worth updating EDR detection rules for suspicious native-process chains. (src: SecurityLab)
- Russia decree enables temporary state management of critical-infrastructure assets after protection failures. A new Russian decree covers property, securities, and ownership stakes of critical-infrastructure owners who fail to adequately protect key facilities — assets may be transferred to temporary management. Significant regulatory escalation for OT operators in Russia and a signal for multinational compliance teams. (src: SecurityLab)
Themes
Living-off-the-land tradeware continues to dominate. The DPRK analysis reinforces a pattern seen across multiple recent campaigns: threat actors increasingly favour native tooling and signed binaries over custom malware to evade EDR — aligning with the ClickFix and SynkLoader social-engineering approaches that rely on legitimate-looking installers rather than exploits.
Dev-tooling remains a soft target. The VS Code MSSQL extension RCE is the latest in a string of developer-toolchain vulnerabilities and supply-chain compromises; extending patching scope beyond OS-level updates to IDE extensions and CI/CD plugins should be standard practice.
