Windows AFD.sys Zero
Lazarus has expanded its long-running Operation Dream Job campaign by exploiting a Windows zero-day vulnerability that grants attackers SYSTEM-level access and helps neutralize endpoint visibility. This DPRK-linked threat actor is specifically targeting defense, aerospace, and aviation organizations worldwide, with recent activity impacting entities in Europe and India. Check Point Research identified the flaw as CVE-2026-68820, […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
