North Korea's Lazarus Group Exploits Microsoft Zero-Day
TL;DR. North Korea's Lazarus Group exploited a zero-day vulnerability in Microsoft products ahead of the latest Patch Tuesday release, impacting systems globally. - Microsoft's August Patch Tuesday addressed 421 bugs, including the zero-day CVE-2026-68820. - Lazarus Group used the flaw, enabling SYSTEM-level code execution without user interaction. - This zero-day was part of Operation Dream Job, targeting defense sector organizations for cyber espionage.
- Microsoft's August Patch Tuesday included 421 bug fixes, with AI-assisted vulnerability disclosures influencing the volume.
- North Korea's Lazarus Group exploited CVE-2026-68820, a use-after-free bug in Windows, as a zero-day in early June.
- The exploit allowed local attackers to gain SYSTEM-level privileges without user interaction.
- Check Point researchers identified the exploit, linking it to Lazarus Group's long-running Operation Dream Job.
- Operation Dream Job uses social engineering to trick job seekers into clicking malicious links or opening malware, aiming for IP theft and cyber spying.
Sources
- 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one — theregister.com
- securityweek.com — securityweek.com