Known Exploited cybersecurity update: Lazarus hackers exploited Windows zero-day to target defense firms. The report references CVE-2026-68820. At least one associated vulnerability is present in the CISA Known Exploited Vulnerabilities catalog, increasing the urgency for affected organizations to review exposure and vendor remediation guidance. NetworkFix reviewed the available source material to summarize the security issue, its potential impact and the defensive actions administrators should prioritize.

What Happened

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. […] Lazarus hackers exploited Windows zero-day to target defense firms North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. Microsoft addressed the flaw in this month's Patch Tuesday security updates , marking it as actively exploited in the wild . Researchers found that the Lazarus threat group has been leveraging it since early July. Microsoft says that the vulnerability is a "use-after-free in Windows Ancillary Function Driver for WinSock (AFD.sys)" that allows an attacker to increase their local privileges. The tech giant added that a locally authenticated user could run a specially crafted application on an affected system to trigger a race condition, eventually gaining SYSTEM privileges without any user interaction. A recent wave of the long-standing Operation Dream Job campaign has been targeting defense, aerospace, and aviation organizations in Europe and India, using fraudulent recruitment offers to employees in target entities. In at least one case, the threat actor compromised an organization in France and used it in spear-phishing attacks on additional targets.

Technical Details

The vulnerability identifiers associated with this report are CVE-2026-68820. Researchers at cybersecurity company Check Point, tracking the latest variant of Operation Dream Job, found that Lazarus incorporated an exploit for CVE-2026-68820 that specifically supported Windows 11 builds 26100 and 26200 into a new version of the FudModule kernel-mode rootkit to elevate privileges. This is not the first time Lazarus exploited a zero-day flaw in AFD.sys to elevate privileges and install the FudModule rootkit on targeted systems. According to the researchers, the latest version of the rootkit features previously documented capabilities such as disabling EDR telemetry and interfering with security products, while also adding Smart App Control tampering. Check Point's analysis revealed that the hackers have also deployed a new backdoor called Troy that supports 17 commands, including the following: Check Point also reported observing scans targeting vulnerable Roundcube installations, which were subsequently compromised with a new PHP web shell dubbed RelayShell. The attacker likely used leaked credentials to authenticate to Roundcube before exploiting CVE-2025-49113 , an authenticated PHP object-deserialization vulnerability, to obtain remote code execution. The researchers have identified at least 17 servers infected with RelayShell, based on the number of identifiers they retrieved. “This new Operation Dream Job campaign focused heavily on the defense sector, particularly organizations involved in military technologies such as surveillance sensors, drones, and robotics,” Check Point says . “The campaign had a global reach, with activity extending into South America, including Brazil, and successful targeting observed in Western Europe, including France and Germany.” The researchers say that its latest findings confirm that Lazarus has further evolved into stealthier operations that adapt to targeted environments. In this case, the attacker abused legitimate web infrastructure (compromised Roundcube instances) to hide malicious communications.

Security Impact

Organizations using the affected technology should treat the report according to its known exploited severity classification. CISA KEV inclusion indicates evidence of exploitation and is a strong signal that remediation should be prioritized rather than handled as a routine maintenance item. Check Point's report shares a list of indicators of compromise related to the attacks, as well as a YARA rule to help detect the RelayShell webshell. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Sonicwall warns of new SMA1000 zero-day exploited in attacks Windows LegacyHive zero-day flaw gets free, unofficial patches New Windows RasMan zero-day flaw gets free, unofficial patches New Windows LegacyHive zero-day gives hackers admin privileges CISA orders feds to patch BlueHammer flaw exploited as zero-day Bill Toulas Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks. Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days LexisNexis shuts down services after suspicious activity on servers Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees Overdue a password health-check? Audit your Active Directory for free See how Skyhigh Security's patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.

Recommended Actions

  • Identify whether the affected product, service or software is present in the environment.
  • Review the original vendor or research advisory and verify affected versions before making configuration changes.
  • Prioritize remediation because the associated CVE appears in the CISA Known Exploited Vulnerabilities catalog.
  • Apply vendor-provided security updates or mitigations as soon as operationally practical.
  • Review relevant security logs and monitoring alerts for signs of suspicious activity associated with the reported issue.
  • Use the CVE identifiers, where available, to validate exposure through vulnerability-management and asset-inventory tools.

Security Details

  • Severity: Known Exploited
  • CVE: CVE-2026-68820
  • CISA KEV: Yes — CVE-2026-68820
  • Original source: BleepingComputer

Why This Matters

Cybersecurity teams should use reports like this as an input to risk-based vulnerability and threat management rather than relying on headline severity alone. Exposure depends on whether the affected technology is deployed, reachable by an attacker and protected by compensating controls. Confirming asset ownership, affected versions and available vendor fixes helps teams prioritize remediation while avoiding unnecessary emergency changes.

Original Report

NetworkFix recommends reviewing the complete original report from BleepingComputer for the authoritative technical context, affected versions, indicators and vendor-specific remediation details: Read the original report.