


Perceptive Security
SOC/SIEM Consultancy

LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn …
Published:
30 juli 2026 om 00:00:00
Alert date:
31 juli 2026 om 00:03:35
Source:
nvd.nist.gov
Security Tools, Identity & Access
CVE-2026-68503 affects the LazyOwn RedTeam/APT Framework, an AI-powered command-and-control (C2) and red-team operations framework. Prior to version 0.2.154, the framework shipped with hardcoded default credentials ('LazyOwn'/'LazyOwn') defined in payload.json and core/payload_schema.py. These credentials were passed unchanged to the lazyc2.py HTTP Basic Authentication handler. Any network-reachable attacker who knows the default credentials can authenticate to the C2 dashboard with full operator-level access. The vulnerability poses a significant risk as the framework is designed for offensive security operations, meaning unauthorized access could lead to serious misuse. The issue has been patched in version 0.2.154, with the fix available via the official GitHub release and commit.
Technical details
Mitigation steps:
Affected products:
LazyOwn RedTeam/APT Framework
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-68503
https://github.com/grisuno/LazyOwn/commit/2e1e3a7b5da8149ae28a970b5883aefa42921652
https://github.com/grisuno/LazyOwn/releases/tag/release/0.2.154
https://github.com/grisuno/LazyOwn/security/advisories/GHSA-38jf-j9x7-jf6f
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
