
This is not afd.sys's first time. It's the FOURTH exploited zero-day in that same driver since 2022: CVE-2024-38193 (also Lazarus) CVE-2025-21418 CVE-2025-32709 CVE-2026-68820 (Lazarus, FudModule) One component, nation-state favorite.
Post summary
The tweet confirms that four zero‑day CVEs in the afd.sys driver have been actively exploited, underscoring ongoing nation‑state activity.

