Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
Reported exploitedWindows AFD.sysLazarus GroupOur summary
Check Point has reported that North Korea's Lazarus Group is actively exploiting a newly patched Windows zero-day vulnerability to compromise systems within the global defense sector. The attacks leverage a use-after-free flaw in the Ancillary Function Driver for WinSock (afd.sys), identified as CVE-2026-68820, to achieve System-level privileges.
Microsoft addressed this critical race condition during its August 2026 Patch Tuesday cycle, and CISA has since added the identifier to its Known Exploited Vulnerabilities catalog. The campaign, dubbed Operation Dream Job, utilizes social engineering tactics involving fake recruitment offers to deliver malware such as Mistpen and ForestTiger.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.