Nknews Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
Article Content
- •CVE-2026-68820 is a zero-day vulnerability exploited by Lazarus Group since early July 2026.
- •The attack vector involves fake job offers targeting defense sector professionals.
- •Microsoft released a patch on August 11, 2026, after confirming active exploitation.
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This vulnerability was actively exploited for weeks before a patch was released on August 11, 2026. The attack method involved fake job offers to lure professionals into downloading malicious software, part of the ongoing Operation Dream Job campaign. Affected organizations include defense contractors and aerospace firms in countries like France, Germany, India, and Brazil. The exploit allows attackers to escalate privileges without user interaction, making it particularly dangerous. The vulnerability has a CVSS score of 7.0 and was added to the CISA Known Exploited Vulnerabilities catalog on the same day the patch was released. Check Point Research reported the vulnerability on July 28, 2026, after observing active exploitation since early July.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (33)
Following this threat?
Track WannaCry, Lazarus and Emotet in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing significant risks to…