CVE-2026-68820Active Exploitation(microsoft / windows_10_1607)

CRITICALCVSS 7.0 · HIGHCISA KEV

Exploitation observed; activity peaked at 75 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

9.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-25. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-416

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 198 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 232 mentions across 29 observed days

What's happening

  • Active exploitation reported across 198 signals
  • Exploit tool or code specified in 16 signals
  • PoC mentioned or linked in 13 signals
  • Patch or workaround mentioned in 133 signals
  • Technical details provided in 147 signals
  • General: 10 classified signals
  • Peaked 27d ago at 75 mentions (2026-08-12); latest day: 1
  • 232 total mentions across 29 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 13 products

Deep dive

Activity timeline232 mentions / 29d
019385675Mentions · 2026-08-11: 17Mentions · 2026-08-12: 75Mentions · 2026-08-13: 50Mentions · 2026-08-14: 9Mentions · 2026-08-15: 8Mentions · 2026-08-16: 7Mentions · 2026-08-17: 10Mentions · 2026-08-18: 7Mentions · 2026-08-19: 4Mentions · 2026-08-20: 5Mentions · 2026-08-21: 3Mentions · 2026-08-22: 1Mentions · 2026-08-23: 5Mentions · 2026-08-24: 3Mentions · 2026-08-25: 5Mentions · 2026-08-26: 1Mentions · 2026-08-27: 1Mentions · 2026-08-28: 2Mentions · 2026-08-29: 1Mentions · 2026-08-31: 4Mentions · 2026-09-01: 3Mentions · 2026-09-03: 3Mentions · 2026-09-04: 2Mentions · 2026-09-08: 1Mentions · 2026-09-11: 1Mentions · 2026-09-12: 1Mentions · 2026-09-14: 1Mentions · 2026-09-22: 1Mentions · 2026-09-24: 1PoC Mentioned / Linked · 2026-08-11: 1PoC Mentioned / Linked · 2026-08-12: 4PoC Mentioned / Linked · 2026-08-13: 4PoC Mentioned / Linked · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-18: 1PoC Mentioned / Linked · 2026-09-04: 1PoC Mentioned / Linked · 2026-09-14: 1Exploit Tool / Code · 2026-08-11: 2Exploit Tool / Code · 2026-08-12: 6Exploit Tool / Code · 2026-08-13: 3Exploit Tool / Code · 2026-08-15: 1Exploit Tool / Code · 2026-08-17: 2Exploit Tool / Code · 2026-08-19: 1Exploit Tool / Code · 2026-08-20: 1Active Exploitation · 2026-08-11: 15Active Exploitation · 2026-08-12: 65Active Exploitation · 2026-08-13: 46Active Exploitation · 2026-08-14: 7Active Exploitation · 2026-08-15: 6Active Exploitation · 2026-08-16: 6Active Exploitation · 2026-08-17: 9Active Exploitation · 2026-08-18: 5Active Exploitation · 2026-08-19: 3Active Exploitation · 2026-08-20: 5Active Exploitation · 2026-08-21: 3Active Exploitation · 2026-08-23: 5Active Exploitation · 2026-08-24: 3Active Exploitation · 2026-08-25: 3Active Exploitation · 2026-08-26: 1Active Exploitation · 2026-08-27: 1Active Exploitation · 2026-08-28: 2Active Exploitation · 2026-08-29: 1Active Exploitation · 2026-08-31: 4Active Exploitation · 2026-09-01: 2Active Exploitation · 2026-09-03: 2Active Exploitation · 2026-09-04: 1Active Exploitation · 2026-09-08: 1Active Exploitation · 2026-09-11: 1Active Exploitation · 2026-09-12: 1Patch / Workaround · 2026-08-11: 12Patch / Workaround · 2026-08-12: 46Patch / Workaround · 2026-08-13: 34Patch / Workaround · 2026-08-14: 4Patch / Workaround · 2026-08-15: 5Patch / Workaround · 2026-08-16: 4Patch / Workaround · 2026-08-17: 5Patch / Workaround · 2026-08-18: 1Patch / Workaround · 2026-08-19: 2Patch / Workaround · 2026-08-20: 2Patch / Workaround · 2026-08-21: 3Patch / Workaround · 2026-08-23: 3Patch / Workaround · 2026-08-24: 2Patch / Workaround · 2026-08-25: 3Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-28: 1Patch / Workaround · 2026-08-31: 3Patch / Workaround · 2026-09-01: 2Technical Details · 2026-08-11: 13Technical Details · 2026-08-12: 47Technical Details · 2026-08-13: 33Technical Details · 2026-08-14: 5Technical Details · 2026-08-15: 5Technical Details · 2026-08-16: 5Technical Details · 2026-08-17: 6Technical Details · 2026-08-18: 2Technical Details · 2026-08-19: 1Technical Details · 2026-08-20: 3Technical Details · 2026-08-21: 2Technical Details · 2026-08-23: 4Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 4Technical Details · 2026-08-26: 1Technical Details · 2026-08-27: 1Technical Details · 2026-08-28: 1Technical Details · 2026-08-31: 4Technical Details · 2026-09-01: 2Technical Details · 2026-09-03: 2Technical Details · 2026-09-04: 2Technical Details · 2026-09-11: 1Technical Details · 2026-09-12: 108-1108-1308-1508-1708-1908-2108-2308-2508-2708-2909-0109-0409-1109-1409-24
Signal classification6 categories
Active Exploitation
17375.5%
Patch
3414.8%
General
104.4%
Disclosure
83.5%
Exploit
31.3%
PoC
10.4%
Referenced assets134 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-1117
Active Exploitation12Patch5
2026-08-1275
Active Exploitation58Disclosure3General3Patch11
2026-08-1350
Active Exploitation40Exploit1General2Patch7
2026-08-149
Active Exploitation6Disclosure1Patch2
2026-08-158
Active Exploitation5General1Patch1
2026-08-167
Active Exploitation5Disclosure1Patch1
2026-08-1710
Active Exploitation7General1Patch2
2026-08-187
Active Exploitation5Disclosure1Patch1
2026-08-194
Active Exploitation2Disclosure1Exploit1
2026-08-205
Active Exploitation5
2026-08-213
Active Exploitation3
2026-08-221
General1
2026-08-235
Active Exploitation5
2026-08-243
Active Exploitation3
2026-08-255
Active Exploitation3General1Patch1
2026-08-261
Active Exploitation1
2026-08-271
Active Exploitation1
2026-08-282
Active Exploitation1Patch1
2026-08-291
Active Exploitation1
2026-08-314
Active Exploitation3Patch1
2026-09-013
Active Exploitation2Patch1
2026-09-033
Active Exploitation2General1
2026-09-042
Disclosure1Exploit1
2026-09-081
Active Exploitation1
2026-09-111
Active Exploitation1
2026-09-121
Active Exploitation1
2026-09-141
PoC1
Full discourse20 posts
  • cr3ghost@cr3ghost
    Exploit

    Windows kernel 0-day. Ring 0 rootkit. EDR visibility disruption. Post-quantum crypto. Lazarus. This attack chain is ridiculous. CVE-2026-68820 is an actively exploited use-after-free in Windows AFD.sys that Lazarus used to jump from a local foothold to SYSTEM and deploy FudModule v3.1 against defense and aerospace targets. And it gets better: • Windows kernel exploitation • FudModule rootkit • ML-KEM post-quantum key exchange • DLL sideloading • In-memory malware • Microsoft Graph + OneDrive C2 • Hijacked infrastructure • Security telemetry disruption Exploit devs and reverse engineers: study the kernel path. Malware analysts: study the implant chain. Red teamers: study the tradecraft. Blue teams + detection engineers: figure out what telemetry is still trustworthy after the attacker reaches Ring 0. Threat intel: this is Lazarus operationalizing serious Windows kernel research in the wild. Fresh technical deep dive: https://cyllex.io/blog/posts/lazarus-ring-0-cve-2026-68820.html?v=1 #0day #WindowsKernel #MalwareAnalysis #ThreatIntel

    Post summary

    The post declares CVE‑2026‑68820, a use‑after‑free in Windows AFD.sys, is being actively exploited by the Lazarus group, details a sophisticated rootkit chain, and references a deep‑dive technical article.

    071236830122.3K
    8.2K followersView on X
  • Check Point Research@_CPResearch_
    Active Exploitation

    0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/ https://t.co/MIGKtH6FlM

    Post summary

    The post announces that Lazarus used the CVE‑2026‑68820 LPE vulnerability in a real‑world campaign against the defense sector, deploying new backdoor tools and leveraging compromised Roundcube servers.

    283431013936.2K
    25.5K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    🛑 398 fixes. One exploited Windows zero-day. Four unauthenticated 9.8 RCEs. Microsoft’s August Patch Tuesday fixes CVE-2026-68820, which can elevate an attacker with existing code execution to SYSTEM. It also closes the RCE half of a SharePoint exploit chain. Here’s what to patch first ➝ https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html

    Post summary

    Microsoft’s August Patch Tuesday addresses 398 vulnerabilities, including CVE‑2026‑68820 which can elevate code execution to SYSTEM, and it also closes the RCE component of a SharePoint exploit chain. The update comes with patch instructions and a warning to prioritize the fixes.

    54521964353.3K
    2.4M followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 WINDOWS ZERO-DAY ALERT: Lazarus exploited an unpatched flaw in AFD.sys (CVE-2026-68820) to get SYSTEM access and deploy FudModule v3.1 undetected. Patched Aug 11 — were you already hit?👇 0-Day Details: https://cybersecuritynews.com/windows-afd-sys-zero-day-exploited/ #cybersecuritynews https://t.co/CcKBhBLXMp

    Post summary

    The post reports that Lazarus exploited the unpatched AFD.sys flaw (CVE-2026-68820) to gain SYSTEM access and deploy FudModule v3.1, with the vulnerability patched on Aug 11.

    6502151509.8K
    73.7K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Lazarus-linked attacks exploit a Windows zero-day for SYSTEM access. Dream Job lures defense and aerospace targets with fake recruiter messages. One chain exploits CVE-2026-68820 for privilege escalation; another uses a trojanized PDF viewer to load the new Troy backdoor. See how the attacks work: https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html

    Post summary

    Lazarus-linked actors are actively exploiting CVE-2026-68820 to gain SYSTEM-level access in attacks against defense and aerospace targets, deploying a new backdoor via a trojanized PDF viewer.

    4250992446.9K
    2.4M followersView on X
  • Ratan Jyoti@reach2ratan
    Active Exploitation

    Active in-the-wild zero-day and privilege escalation attacks targeting the Windows kernel and core OS execution layer center on several key vulnerabilities added to CISA's Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-68820 (Windows Kernel Ancillary Function Driver - afd.sys): A high-severity use-after-free race condition in the kernel-mode socket driver. Attackers already possessing low-privilege execution run crafted applications to trigger the condition and elevate privileges to NT AUTHORITY\SYSTEM without user interaction. Threat actors frequently chain afd.sys zero-days with remote code execution (RCE) vectors or browser sandbox escapes. CVE-2026-85880 (Windows Advanced Local Procedure Call - ALPC): A heap-based buffer overflow in the ALPC communication mechanism. Confirmed exploited in the wild, this flaw allows an attacker executing code inside a sandboxed, low-privilege AppContainer to escape isolation and gain SYSTEM privileges locally. CVE-2026-81963 (Windows Update Stack Link Following): An improper link resolution vulnerability exploited in targeted zero-day attacks to force the update subsystem to follow malicious symbolic links and overwrite protected system components, granting SYSTEM access. Common Attack Pattern Because these are Local Privilege Escalation (LPE) vulnerabilities, threat actors do not use them for initial access across the network. Instead, they appear as Stage 2 in exploit chains: Initial Compromise: Phishing payload, malicious document, or browser drive-by execution within a sandboxed context. Kernel Exploitation: Triggering the driver or ALPC flaw to bypass Kernel Patch Protection (PatchGuard) or Virtualization-Based Security (VBS) boundaries. Payload Delivery: Disabling EDR agents directly from kernel space (Bring Your Own Vulnerable Driver/direct kernel write techniques) and dumping LSASS credentials for lateral movement. Several in‑the‑wild Windows kernel LPE zero‑days are now on CISA’s KEV: CVE‑2026‑68820 (afd.sys), CVE‑2026‑85880 (ALPC) and CVE‑2026‑81963 (update link‑follow). Attackers use these as stage‑2 after initial compromise to escape sandboxes, gain SYSTEM, disable EDR and dump creds. #WindowsSecurity #CVE202668820, #AfdSys, #ZeroDay, #KernelExploit, #PrivilegeEscalation, #EoP, #WindowsSecurity, #ThreatIntel, #OperationDreamJob, #FudModule, #Rootkit, #APT, #CyberSecurity, #InfoSec, #PatchTuesday, #CISA, #KEV, #BlueTeam, #VulnerabilityManagement #ShieldCrash

    Post summary

    The text documents multiple Windows kernel vulnerabilities that are actively exploited in the wild as stage‑2 privilege‑escalation tools, detailing technical flaws and typical attack chains.

    022030101.2K
    26.9K followersView on X
  • Virus Bulletin@virusbtn
    Active Exploitation

    Check Point researchers look at the latest variant of the Operation Dream Job campaign where the threat actor exploited CVE-2026-68820, a 0day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of Lazarus’s kernel-mode rootkit FudModule https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/ https://t.co/fAJKINtII2

    Post summary

    The post reports that threat actors actively exploited CVE‑2026‑68820, a 0‑day flaw in Microsoft’s AFD.sys driver, to deploy a kernel‑mode rootkit, confirming real‑world exploitation with no mention of patches or PoC details.

    09039122.6K
    61.6K followersView on X
  • Space Programmer@Spaceprogrammer
    Active Exploitation

    🚨 Hoy en ciberseguridad México: 🔴 Microsoft Patch Tuesday agosto — 400+ vulnerabilidades. Una ya está siendo explotada activamente por actores norcoreanos. CVE-2026-68820 — zero-day en el driver de sockets de Windows. Permite escalar a SYSTEM desde una cuenta con privilegios bajos. Si tienes Windows sin parchear — ya entraron o están intentando entrar. 🔴 Microsoft Teams — CVSS 10.0. Elevación de privilegios sin autenticación. La herramienta de trabajo de prácticamente todo el gobierno y empresas mexicanas. 🔴 México tiene un déficit de 77,000 especialistas en ciberseguridad. 400+ vulnerabilidades nuevas este mes. 77,000 personas que no existen para responderlas. Y un Patch Tuesday que no espera a nadie. 📎 Help Net Security / Infobae / MSRC — 12/08/2026 http://helpnetsecurity.com/2026/08/12/august-2026-patch-tuesday-cve-2026-68820/

    Post summary

    The post announces that CVE‑2026‑68820, a zero‑day escalating to SYSTEM, is being actively exploited by North Korean actors and warns unpatched Windows systems.

    01113322.7K
    74.0K followersView on X
  • COLCERT@colCERT
    Active Exploitation

    📢El #ColCERT emite una nueva #AlertaDeSeguridad sobre Operation Dream Job, una campaña que incorpora la explotación de la vulnerabilidad CVE-2026-68820 en Windows. 👉Consulta la alerta y fortalece las medidas de prevención: https://www.colcert.gov.co/800/w3-article-440371.html https://t.co/eOB56r4FdR

    Post summary

    ColCERT’s alert highlights that the Operation Dream Job campaign actively exploits CVE-2026-68820 on Windows, underscoring current in‑the‑wild usage.

    01002161.9K
    12.4K followersView on X
  • blackorbird@blackorbird
    Active Exploitation

    Operation Dream Job #Lazarus exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit. https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/ Lazarus also used CVE-2025-49113 to exploit vulnerable Roundcube webmail servers. The compromised servers were infected with RelayShell, a PHP webshell that repurposes compromised web servers as relay nodes within the attacker’s command-and-control infrastructure.

    Post summary

    Lazarus Group is actively exploiting CVE‑2026‑68820 in Microsoft AFD.sys to deploy the kernel‑mode rootkit FudModule and CVE‑2025‑49113 to compromise Roundcube servers, installing the RelayShell webshell for command‑and‑control.

    1602162.9K
    43.8K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️We added Cisco Secure Firewall vulnerability CVE-2026-20349, Microsoft Windows vulnerability CVE-2026-68820 & Metabase vulnerability CVE-2026-72898 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity https://t.co/iahRvhwOoT

    Post summary

    The tweet announces that three CVEs (Cisco Secure Firewall, Microsoft Windows, Metabase) have been added to the DHS KEV Catalog and directs readers to a link to apply mitigations, indicating these vulnerabilities are actively exploited or pose a high risk.

    27022210.1K
    302.7K followersView on X
  • VOA 한국어@voakorea
    Active Exploitation

    미국 국토안보부 산하 사이버보안·인프라보안국(CISA)이 12일 마이크로소프트와 함께 윈도우 운영체제의 보안 결함(CVE-2026-68820)이 실제 공격에 악용되고 있다고 확인했습니다. https://www.voakorea.com/a/cisa-windows-vulnerability-north-korean-attack-2026-081326/8186032.html https://t.co/KbqumrOucb

    Post summary

    CISA reports that Microsoft Windows CVE‑2026‑68820 is currently being exploited in real attacks.

    080170662
    12.6K followersView on X
  • Ayed Alosaimi | تحليل سيبراني@Ayed_Alosaimi
    Active Exploitation

    يصل المهاجم إلى جهاز ويندوز بصلاحيات مستخدم عادي… ثم يستغل خطأً داخل النواة ليصبح NT AUTHORITY\SYSTEM، أعلى سلطة في النظام، ويفتح الطريق لتعطيل رؤية أدوات الحماية. هذا ليس سيناريو نظريًا؛ بل ثغرة يوم صفر استغلتها Lazarus فعليًا: CVE-2026-68820. وراء كل اختراق… قصة 👇 لكن انتبه: الثغرة لم تُدخل المهاجم إلى الجهاز عن بُعد. في Operation Dream Job، بدأت السلسلة بعرض وظيفة مزيف وملفات أو عارضات PDF ملغّمة. وبعد تشغيل البرمجية الخبيثة وحصولها على موطئ قدم محلي، جاء دور الثغرة لرفع الصلاحيات. نقطة التحول كانت afd.sys، وهو برنامج تشغيل داخل نواة ويندوز يعالج عمليات WinSock. الثغرة من نوع Use-After-Free: تُحرر مساحة في ذاكرة النواة، لكن مسارًا آخر يستمر في استخدامها. وهنا يتحول خطأ في إدارة الذاكرة إلى فرصة للسيطرة داخل النواة. كيف يحدث ذلك؟ تتعامل عدة خيوط مع حالة socket في الوقت نفسه دون تزامن كافٍ، فتقع Race Condition. وإذا نجح المهاجم في استغلالها، يحصل على Kernel Read/Write؛ أي قدرة القراءة والكتابة داخل ذاكرة النواة، ثم يرتقي إلى SYSTEM. أما التفاصيل الكاملة للاستغلال فلم ينشرها الباحثون. الوصول إلى SYSTEM لم يكن النهاية. استُخدمت الصلاحيات لتشغيل FudModule، وهو Rootkit على مستوى النواة، وحقن حمولة داخل عملية SYSTEM وتعطيل رؤية EDR. لذلك كانت ثغرة مصنفة High بدرجة 7.0 شديدة الخطورة عمليًا: السياق الهجومي أخطر من الرقم. الدفاع يبدأ من كسر السلسلة: • تثبيت تحديثات Microsoft الصادرة في 11 أغسطس 2026. • حصر الأنظمة غير المحدثة، خصوصًا الحرجة. • رصد الانتقال المفاجئ من مستخدم عادي إلى SYSTEM. • منع البرامج وعارضات PDF غير الموثوقة. EDR وApplication Control لا يعوضان التصحيح. أدرجت CISA الثغرة ضمن KEV لأنها مستغلة فعليًا. Microsoft MSRC: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820 Check Point Research: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/ CISA KEV: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-68820 لا أنقل الخبر فقط… أشرح ما وراءه.

    Post summary

    The post confirms CVE-2026-68820, a high‑severity Windows kernel use‑after‑free flaw, was actively exploited by Lazarus in the wild, provides technical details and mitigation advice, and cites official patch and CISA KEV references.

    0201141.3K
    34.9K followersView on X
  • 月城紫音@siontukisiro
    Active Exploitation

    #Windows11 #WindowsUpdate #セキュリティ Windows 11利用者は、Windows Updateを確認してください⚠️ Microsoftが公開した CVE-2026-68820。 攻撃に成功するとSYSTEM権限を奪われる可能性があり、動画内で扱っているMicrosoft情報では悪用も確認されています。 ただし、 ネットにつないでいるだけで無条件に攻撃される話ではありません。 条件と対策を54秒でまとめました👇🌙 https://youtube.com/shorts/nyCCWcmYGFs?feature=share

    Post summary

    The post announces CVE-2026-68820 and states that exploitation has been confirmed by Microsoft, but provides no PoC, tool, patch information, or technical details.

    110141502
    978 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    🚨 مهم جداً مجموعة Lazarus التابعه لكوريا الشمالية تستغل حالياً ثغره CVE-2026-68820 الي تم اصلاحها في تحديث هذا الاسبوع من مايكروسفت الثغرة في AFD.sys وتسمح للمهاجم تصعيد صلاحياته الى SYSTEM التفاصيل: 🧵👇 https://t.co/4522nrlN0w

    Post summary

    The tweet reports that the Lazarus group is actively exploiting CVE-2026-68820, a privilege‑elevation flaw in AFD.sys that was patched by Microsoft this week.

    121832.2K
    50.2K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Disclosure

    Check Point Research documented Lazarus’ Operation Dream Job campaign evolving with a zero-day AFD.sys exploit (CVE-2026-68820), trojanized PDF viewers, RelayShell C2 infrastructure, and the new Troy backdoor. https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/

    Post summary

    Check Point Research announced a new zero‑day vulnerability CVE‑2026‑68820 in AFD.sys tied to Lazarus Operation Dream Job, detailing malware components, but did not provide PoC, exploit code, or patch information.

    02075938
    22.9K followersView on X
  • FearsOff Cybersecurity@FearsOff
    Active Exploitation

    North Korea used servers vulnerable to a bug we found as C2 in its latest campaign targeting the defence, aerospace, and aviation sectors. Check Point's report last week: Lazarus exploited a Windows kernel zero-day, CVE-2026-68820 in afd.sys, since at least early July against defense, aerospace and aviation targets in France, Germany, Brazil and India. The campaign ran two parallel infection chains. One used signed-binary DLL sideloading to execute MISTPEN in memory. The other used a trojanized PDF viewer to deploy a new backdoor, Troy. Both could escalate to SYSTEM through CVE-2026-68820, followed by a new FudModule build designed to disable EDR visibility. MISTPEN ultimately deployed ForestTiger for long-term access. Microsoft patched the zero-day on 11 August. Much of the C2 infrastructure wasn't theirs. Check Point found compromised Roundcube, WordPress and PrestaShop servers being used as relay infrastructure. It assesses that Lazarus likely authenticated to vulnerable Roundcube servers using leaked credentials, exploited CVE-2025-49113, and planted RelayShell. The researchers identified at least 17 likely relay nodes. One compromised organization headquartered in France was then used to spear-phish targets worldwide - borrowing a legitimate organization's infrastructure and reputation to make the messages more credible. CVE-2025-49113 is ours. Our co-founder @k_firsov discovered and reported it in May 2025: authenticated RCE via PHP object deserialization, CVSS 9.9, sitting in the Roundcube codebase for more than a decade. Roundcube patched it on 1 June 2025. Attackers diffed and weaponized the vulnerability within 48 hours of the patch becoming available, with a working exploit offered for sale days later. We published the full technical breakdown to give defenders parity. CISA added CVE-2025-49113 to its Known Exploited Vulnerabilities catalog in February 2026, with a 13 March remediation deadline for covered US federal agencies. And Lazarus was still exploiting unpatched Roundcube servers in this campaign. We know the tradecraft because we spend our year on the other end of it. Lazarus is heavily involved in cryptocurrency theft, and we run continuous adversarial simulation against exchanges and protocols that sit high on the DPRK targeting list. The objectives differ, but the tradecraft overlaps: recruitment lures, signed-binary sideloading, credential theft, and kernel-level evasion. Theft there. Espionage here. If you build aircraft, satellites, drones, avionics, sensors or related defense technology, your engineers fit the targeting profile. And your internet-facing Roundcube, WordPress or PrestaShop infrastructure can become someone else's C2 if it isn't secured and patched. We find the bugs that might end up in campaigns like this one. We also run the campaign against our own clients first, on purpose, with a scope document. Our research: https://lnkd.in/dzS-RYcz

    Post summary

    The post reports that the Lazarus group used CVE‑2026‑68820 and CVE‑2025‑49113 in real attacks against defense sectors, includes PoC and exploit details, and notes recent patches while confirming active exploitation.

    13072638
    2.1K followersView on X
  • sheihk@_Labzy
    Active Exploitation

    North Korean hackers already used this zero-day before it was patched. Cyber Pulse 🛡️🦅 Microsoft’s August Patch Tuesday fixed a Windows kernel zero-day CVE-2026-68820 that Lazarus Group had already been exploiting in the wild. The flaw allowed attackers to gain SYSTEM privileges. If you haven’t applied the latest Windows updates, do it now. How quickly does your organisation usually roll out critical Microsoft patches? #CyberSecurity #ZeroDay #CurrentThreats

    Post summary

    The post highlights that the CVE‑2026‑68820 Windows kernel zero‑day was actively exploited by Lazarus Group and has been patched in Microsoft’s August Patch Tuesday.

    14080368
    6.8K followersView on X
  • Es Geeks@EsGeeks
    Active Exploitation

    🚨 Lazarus explota zero-day en Windows (CVE-2026-68820) Falsa oferta de trabajo → elevación a SYSTEM vía AFD.sys → rootkit FudModule + backdoor Troy. Ya hay targets en defensa (incluye Brasil). Parche de Patch Tuesday YA. No esperes. #ZeroDay #Lazarus #Windows https://t.co/liRWPe3Oh2

    Post summary

    A zero‑day CVE‑2026‑68820 on Windows is being exploited by Lazarus with AFD.sys privilege escalation and rootkit/backdoor components, targeting defense sectors, but a Patch Tuesday fix is already available.

    100101812
    22.5K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Active Exploitation

    Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor. #Lazarus #ZeroDay #CVE202668820 #OperationDreamJob #Cybersecurity #DPRK #FudModule #DefenseSector http://securityonline.info/lazarus-zero-day-dream-job/

    Post summary

    The post reports that Lazarus actively exploited the Windows zero‑day CVE‑2026‑68820 in Operation Dream Job, targeting defense firms with fake job offers and a backdoor. No technical details, PoC, or mitigation are provided.

    01056685
    13.0K followersView on X
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_11_25h2---
OSmicrosoftwindows_11_26h1---
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2025---

Explore more