Lazarus Targeted Defense Firms via Windows Zero-Day
Lazarus exploited a Windows zero-day in afd.sys targeting defense firms via Operation Dream Job. CISA issued a two-week federal patch mandate.
Exploitation confirmed. North Korea’s Lazarus Group weaponized CVE-2026-68820 — a use-after-free in the Windows Ancillary Function Driver for WinSock (afd.sys) — against defense-sector targets before Microsoft issued a patch last Tuesday. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and set a binding two-week deadline for federal agencies. Federal patch cutoff: August 26.
The campaign: Operation Dream Job
Delivery mechanism: fake recruitment lures. Lazarus’ long-running Operation Dream Job uses fraudulent recruiter contact, skill assessments, and document delivery chains aimed at defense and aerospace employees. Social engineering for initial access; CVE-2026-68820 for the escalation.
The Record reports that researchers uncovered the zero-day while investigating this exact campaign — attackers exploiting the job application process to get inside, then escalating from there.
What the bug does
CVE-2026-68820 is a local privilege escalation, not remote code execution on its own. CVSS 7.0, severity: high. A race condition in afd.sys corrupts freed memory, escalating a restricted local session to SYSTEM. It converts post-access execution into full system control.
SecurityWeek reports ForestTiger — a backdoor attributed to Lazarus — was deployed following successful exploitation. Attribution: researcher-assessed per vendor reporting.
Patch status
Fixed in the August 2026 Patch Tuesday cumulative update — the same release that addressed 400+ other flaws. Applies to all currently supported Windows versions. No workaround exists for a kernel driver flaw of this class. Patching is the only remediation.
Full technical detail: NVD entry for CVE-2026-68820.
Action required
The CISA binding directive covers federal civilian agencies. Confirmed Lazarus targeting of defense contractors means the private sector — cleared facilities, defense-adjacent suppliers — cannot treat this as a grace-period situation.
If endpoints haven’t received the August 2026 cumulative update: patch now. Active exploitation of a zero-day by a sophisticated state actor means exposure time costs more than patch downtime.
- [ HIGH ] CVE-2026-68820 Windows AFD WinSock Use-After-Free Privilege Escalation
Found this useful? Share it.


