CVE Tools

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

SecurityWeekBy Ionut Arghire

Reported exploitedWindows AFD.sysLazarus Group

Our summary

Check Point has reported that North Korea's Lazarus Group is actively exploiting a newly patched Windows zero-day vulnerability to compromise systems within the global defense sector. The attacks leverage a use-after-free flaw in the Ancillary Function Driver for WinSock (afd.sys), identified as CVE-2026-68820, to achieve System-level privileges.

Microsoft addressed this critical race condition during its August 2026 Patch Tuesday cycle, and CISA has since added the identifier to its Known Exploited Vulnerabilities catalog. The campaign, dubbed Operation Dream Job, utilizes social engineering tactics involving fake recruitment offers to deliver malware such as Mistpen and ForestTiger.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store