Lazarus Group Exploits Windows Zero-Day to Target Defense Firms

Lazarus Group Exploits Windows Zero-Day to Target Defense Firms

First seen 12 Aug 2026, 13:36 UTC NknewsFeeds2.Feedburner 72% similarity 78.0

Article Content

Browse articles
ThreatCluster

North Korean hackers from the Lazarus Group have exploited a zero-day vulnerability in Microsoft Windows, identified as CVE-2026-68820, to target defense organizations. This campaign, part of Operation Dream Job, involves using fake job offers to lure victims, coupled with trojanized PDF software. The zero-day flaw, affecting a Windows component for network connections, was actively exploited since early July 2026 and allows attackers to gain high-level system privileges. Israeli cybersecurity firm Check Point reported these findings on August 12, 2026. The attacks primarily focus on defense sector firms, indicating a significant risk to national security. The vulnerability was publicly disclosed on August 11, 2026, and is currently under active exploitation.

Key Points: • Lazarus Group exploits CVE-2026-68820, a zero-day vulnerability in Windows. • Attackers use fake job offers and trojanized PDFs to target defense organizations. • The vulnerability allows high-level system access, posing a significant threat.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
CVE-2026-68820 published
Microsoft disclosed a zero-day vulnerability affecting Windows network components, allowing high-level access.
Nknews
2026-08-11
CVE-2026-68820 added to CISA KEV
CISA confirmed active exploitation of the Windows zero-day vulnerability in the wild.
Nknews
2026-08-12
Lazarus Group's campaign reported
Check Point reported on the Lazarus Group's exploitation of the zero-day and their use of fake job offers.
Feeds2.Feedburner

Community

Browse all →

Tracked Entities in This Story