CVE Tools

Microsoft выпустила патчи более чем для 400 уязвимостей

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedWindowsLazarusafd.sys

Our summary

Microsoft released its August security updates addressing 421 vulnerabilities, three of which were classified as zero-days. Most notably, CVE-2026-68820, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys), has been actively exploited by the North Korean threat group Lazarus.

Researchers attribute this exploitation to the "Operation Dream Job" campaign, where attackers targeted defense organizations in Europe and India using fake job offers from companies like Lockheed Martin and Enveil. Upon compromising systems via a modified PDF reader called SecurityPDF and implanting the Troy backdoor, threat actors leveraged CVE-2026-68820 to escalate privileges to SYSTEM level and deploy the FudModule rootkit.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store