Skip to content
feed: live
>_ 0dayNews
microsoft
● Breaking

Lazarus Targeted Defense Firms via Windows Zero-Day

Lazarus exploited a Windows zero-day in afd.sys targeting defense firms via Operation Dream Job. CISA issued a two-week federal patch mandate.

Lazarus Targeted Defense Firms via Windows Zero-Day
Image: AI-generated — no human photographer / 0dayNews AI Cover (comfyui) · Generated on-site infrastructure — no external license
airgap airgap · Published · 1 min read

Exploitation confirmed. North Korea’s Lazarus Group weaponized CVE-2026-68820 — a use-after-free in the Windows Ancillary Function Driver for WinSock (afd.sys) — against defense-sector targets before Microsoft issued a patch last Tuesday. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and set a binding two-week deadline for federal agencies. Federal patch cutoff: August 26.

The campaign: Operation Dream Job

Delivery mechanism: fake recruitment lures. Lazarus’ long-running Operation Dream Job uses fraudulent recruiter contact, skill assessments, and document delivery chains aimed at defense and aerospace employees. Social engineering for initial access; CVE-2026-68820 for the escalation.

The Record reports that researchers uncovered the zero-day while investigating this exact campaign — attackers exploiting the job application process to get inside, then escalating from there.

What the bug does

CVE-2026-68820 is a local privilege escalation, not remote code execution on its own. CVSS 7.0, severity: high. A race condition in afd.sys corrupts freed memory, escalating a restricted local session to SYSTEM. It converts post-access execution into full system control.

SecurityWeek reports ForestTiger — a backdoor attributed to Lazarus — was deployed following successful exploitation. Attribution: researcher-assessed per vendor reporting.

Patch status

Fixed in the August 2026 Patch Tuesday cumulative update — the same release that addressed 400+ other flaws. Applies to all currently supported Windows versions. No workaround exists for a kernel driver flaw of this class. Patching is the only remediation.

Full technical detail: NVD entry for CVE-2026-68820.

Action required

The CISA binding directive covers federal civilian agencies. Confirmed Lazarus targeting of defense contractors means the private sector — cleared facilities, defense-adjacent suppliers — cannot treat this as a grace-period situation.

If endpoints haven’t received the August 2026 cumulative update: patch now. Active exploitation of a zero-day by a sophisticated state actor means exposure time costs more than patch downtime.

Related CVEs
  • [ HIGH ] CVE-2026-68820 Windows AFD WinSock Use-After-Free Privilege Escalation

Found this useful? Share it.