The Lazarus group, linked to North Korea, is exploiting a newly discovered Windows zero-day vulnerability (CVE-2026-68820) in the AFD.sys driver, which provides SYSTEM-level access. This vulnerability is being leveraged…
CrowdStrike has reclassified the North Korea-linked intrusion set LABYRINTH CHOLLIMA into three distinct units: GOLDEN CHOLLIMA and PRESSURE CHOLLIMA, which focus on cryptocurrency theft, and the core LABYRINTH CHOLLIMA…