Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This vulnerability was actively exploited for weeks before a patch was released on August 1...
The Russian threat group Sandworm has been targeting IT professionals through a social engineering campaign since May 2026. The campaign, attributed to the UAC-0145 subgroup, involves impersonating IT companies and recruiters to lure victims into downloading a trojanized WireGuard VPN client. Victim...
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that could steal GitHub tokens. The updates are crucial for protecting a wide range of Mi...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of active exploitation of a Microsoft Windows vulnerability, CVE-2026-68820, which is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock. This vulnerability allows an authorized attacker to elevate pr...