Lazarus Group Exploits Windows Zero-Day to Target Defense Sector

Lazarus Group Exploits Windows Zero-Day to Target Defense Sector

First seen 12 Aug 2026, 10:24 UTC CybersecuritynewsGbhackersNknewsFeeds2.FeedburnerInfosecurity-Magazine+21 81.0

Article Content

Browse articles
ThreatCluster

The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This vulnerability was actively exploited for weeks before a patch was released on August 11, 2026. The attack method involved fake job offers to lure professionals into downloading malicious software, part of the ongoing Operation Dream Job campaign. Affected organizations include defense contractors and aerospace firms in countries like France, Germany, India, and Brazil. The exploit allows attackers to escalate privileges without user interaction, making it particularly dangerous. The vulnerability has a CVSS score of 7.0 and was added to the CISA Known Exploited Vulnerabilities catalog on the same day the patch was released. Check Point Research reported the vulnerability on July 28, 2026, after observing active exploitation since early July.

Key Points: • CVE-2026-68820 is a zero-day vulnerability exploited by Lazarus Group since early July 2026. • The attack vector involves fake job offers targeting defense sector professionals. • Microsoft released a patch on August 11, 2026, after confirming active exploitation.

Timeline

2024-08-13
CVE-2024-38193 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-02-11
CVE-2025-21418 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-05-13
CVE-2025-32709 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-06-02
CVE-2025-49113 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-55040 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-28
Vulnerability reported to Microsoft
Check Point Research reported CVE-2026-68820, a zero-day vulnerability in afd.sys, to Microsoft.
Techtimes
2026-08-05
CVE-2026-68820 assigned
Microsoft formally assigned CVE-2026-68820 after confirming the vulnerability.
Techtimes
2026-08-06
CVE-2026-65400 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-06
CVE-2026-65667 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-11
Patch released for CVE-2026-68820
Microsoft released a patch for the actively exploited zero-day vulnerability in afd.sys as part of August Patch Tuesday.
Buttondown