North Korea hid a Windows zero-day inside fake job offers for five weeks

Lazarus used a bug in a core Windows driver to grab SYSTEM access and disable antivirus — Microsoft patched it Tuesday, weeks after North Korea…

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-68820 is a use-after-free race condition in afd.sys, the kernel driver behind Windows' entire WinSock networking stack.

The short version

Check Point Research attributes exploitation to Lazarus Group's Operation Dream Job campaign, active since roughly July 7, 2026 — patched only on August 11.

The short version

The exploit deploys FudModule v3.1, a kernel-mode rootkit that disables Windows Defender, kills EDR processes and suppresses crash dumps.

The short version

Targets are concentrated in defense, aerospace, aviation, drone and robotics companies across the US, France, Germany, Brazil and India, lured with fake job offers.

The short version

Microsoft patched 421 CVEs total in its August 2026 Patch Tuesday; CVE-2026-68820 is the one confirmed actively exploited in the wild.

If you're in one of these industries

Patch Windows now — CVE-2026-68820 is fixed in the August 11 update. Beyond that, the actual entry point here was never the kernel bug; it was a convincing DM from a fake recruiter. Treat…

Aliteq

Read the full story

North Korea hid a Windows zero-day inside fake job offers for five weeks

Read the full story on Aliteq