Skip to content

Lazarus Hackers Actively Exploiting Windows AFD.sys Zero

Cybersecuritynews •Guru Baran • August 12, 2026

North Korea’s Lazarus group has been caught exploiting a Windows kernel 0-day vulnerability to deploy an upgraded version of its notorious FudModule rootkit, according to new research from Check Point Research. The flaw, now tracked as CVE-2026-68820, lives inside AFD.sys, the Ancillary Function Driver that manages network sockets deep within the Windows kernel. Microsoft patched […]

Extracted Entities

APT Groups (1)

Attack Types (2)

Countries (1)

Malware (1)

Platforms (1)