North Korean hackers had a Windows bug for weeks before Microsoft even knew about it

Check Point caught the exploit chain in the wild before Microsoft's own August Patch Tuesday shipped the fix — and this one installs a kernel-mode…

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-68820 is a use-after-free bug in AFD.sys, the Windows driver behind the Windows Sockets API — CVSS 7.0, local privilege escalation to SYSTEM.

The short version

Check Point linked active exploitation to a new wave of North Korea's Operation Dream Job campaign, in use since at least early July 2026.

The short version

Successful exploitation deploys a kernel-mode rootkit, not just a privilege bump — it's a foothold-to-full-control chain.

The short version

Microsoft shipped the fix August 11 as part of a 421-CVE Patch Tuesday, its largest single batch tracked this year.

The short version

It needs local code execution first — this isn't a remote, walk-up bug like the Gitea or Citrix flaws also making news this week.

Aliteq

Read the full story

North Korean hackers had a Windows bug for weeks before Microsoft even knew about it

Read the full story on Aliteq