CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
CISA orders federal agencies to patch exploited Windows Winsock zero-day CVE-2026-68820 by August 25, used by Lazarus in Operation Dream Job.
CISA ordered federal agencies to patch Windows Winsock vulnerability CVE-2026-68820, rated 7/10, by August 25 after confirming exploitation; no workaround exists and a restart is required. Check Point found Lazarus Group hackers impersonated Lockheed Martin and Enveil recruiters on LinkedIn, sent malicious PDFs enabling long-term remote access, then used the zero-day to escalate from limited access to full system control. Targets spanned defense sectors including surveillance, drones and robotics in France, Germany, Brazil and India, as part of Operation Dream Job tracked since 2020.
- CISA set an August 25 patch deadline; no workaround exists and a device restart is required
- Check Point found Lazarus impersonated Lockheed Martin and Enveil recruiters with malicious PDFs
- The Winsock flaw lets malware escalate from limited access to complete system control
- Targets spanned defense sectors in France, Germany, Brazil and India
- The same Winsock component was previously exploited by Lazarus Group in 2024
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-68820 | Use-After-Free Local Privilege Escalation in Microsoft Windows WinSock AFD Driver CVE-2026-68820 is a use-after-free (CWE-416) in the Windows Ancillary Function Driver for WinSock (afd.sys), the kernel component that handles Winsock socket operations. A local, authenticated attacker can trigger the memory corruption through crafted socket activity, and the high attack-complexity score (AV:L/AC:H/PR:L) indicates exploitation requires a specific, likely race-sensitive sequence of operations. Successful exploitation elevates privileges to SYSTEM, giving the attacker full control of the host, and public reporting describes deployment of a backdoor after privilege escalation. Virtually every Windows 10, Windows 11, and Windows Server (2012-2022) installation ships this driver, so the affected population is essentially the entire supported Windows installed base. The flaw is being exploited in the wild: CISA added it to the KEV on 2026-08-11, Microsoft fixed it in the August 2026 Patch Tuesday release, and reporting ties active exploitation to North Korea's Lazarus group, who paired the zero-day with fake job-offer lures. Do: Apply Microsoft's August 2026 security updates for all listed Windows 10, Windows 11, and Windows Server versions as a priority; CISA KEV (added 2026-08-11) requires federal agencies to patch within two weeks in accordance with BOD 26-04. Because observed attacks used fake job-offer social engineering to reach local code execution, prioritize user workstations and review endpoints for unexplained SYSTEM-level process activity, newly installed services, or backdoor persistence artifacts. Where patching is deferred, restrict execution of untrusted local code on affected hosts and monitor for privilege-escalation events. | 7.0 | 6% | KEV |
| masshundreds of millions to over 1 billion Windows devices and servers (essentially all endpoints running the listed Windows 10/11/Server versions) |
Full article688 words · extracted from therecord.media · click to collapse
Federal agencies were ordered to patch a Windows vulnerability used by North Korean hackers to target people applying to jobs in the defense and aerospace industry. The Cybersecurity and Infrastructure Security Agency (CISA) and Microsoft confirmed on Tuesday that CVE-2026-68820 is being exploited. The bug was the only vulnerability in Microsoft’s Patch Tuesday release that the company confirmed is being used in real-world attacks. The vulnerability impacts Winsock, a tool that acts as a bridge allowing web browsers to connect to the internet. Nightwing's Nick Carroll compared the bug, which carries a seven out of ten severity score, to an intruder slipping through a closing door to print their own all-access VIP badge for a secure facility. CISA gave federal agencies until August 25 to patch the bug. A device restart is required and there is no workaround to the issue. Automox CTO Jason Kikta noted that the same component was previously exploited in 2024 by the Lazarus Group, an infamous hacking operation run out of North Korea’s Reconnaissance General Bureau. Kikta said the vulnerability requires two steps: an attacker would need to phish their way into a low-privileged foothold before using it. “Treat this as the month's deadline item. It's the one confirmed-exploited bug in the release, and it applies to every Windows endpoint you manage. Put the noise to work. This exploitation pattern is detectable, but only if your detection actually covers kernel-driver race abuse,” Kikta added. Check Point said it disclosed the bug to Microsoft after discovering it as part of its examination into the latest wave of attacks that are part of Operation ‘Dream Job’ — a long-running campaign by North Korean hackers to exploit the job application process. A Check Point report released on Tuesday said Lazarus Group hackers impersonated recruiters for Lockheed Martin and privacy-tech firm Enveil, contacting people on LinkedIn and other sites before sending candidates malicious PDF files. Once the files are opened, a backdoor is enabled that provides Lazarus hackers with long term remote access. Check Point researchers explained that the malware first gathers information about the infected device before deploying an exploit for CVE-2026-68820. They initially thought the issue was related to a past vulnerability fixed last year but further testing proved it was a new bug. The flaw “allows an attacker who has already gotten malware onto a machine to escalate from limited access to complete control of it, the kind of control normally reserved for the operating system itself.” Sergey Shykevich, director of threat intelligence at Check Point, said what made the campaign dangerous is not just the zero-day vulnerability but Lazarus’ ability to weave legitimate, trusted infrastructure into every stage of the attack. “They hid in plain sight, behind top-ranked search results, real vendor branding, and the reputation of organizations they had already compromised,” he said. “When the website, the download and the recruiter all appear authentic, the old advice to 'spot the phishing link' is no longer easily applicable.” The researchers found targets spanning several defense sectors — including surveillance sensors, drones and robotics — in France, Germany, Brazil and India. Threat researchers at several companies have been tracking the Operation DreamJob campaign since 2020. Google warned in 2022 that 250 people working for 10 different news media, domain registrars, web hosting providers and software vendors were targeted by the campaign, receiving malicious emails from fake recruiters claiming to be from Disney, Google and Oracle. ESET previously tracked compromises related to the campaign in India, Poland, the U.K. and most recently Italy. CISA’s decision to order federal agencies to patch the bug comes after FBI officials said they are currently investigating an incident where an unidentified federal agency mistakenly hired an IT worker from North Korea as part of the country’s long-running campaign to infiltrate organizations globally. Operation ‘Dream Job’
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-gives-federal-agencies-two-weeks-to-patch-dprk-microsoft-bug