Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-25. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Windows kernel 0-day.
Ring 0 rootkit.
EDR visibility disruption.
Post-quantum crypto.
Lazarus.
This attack chain is ridiculous.
CVE-2026-68820 is an actively exploited use-after-free in Windows AFD.sys that Lazarus used to jump from a local foothold to SYSTEM and deploy FudModule v3.1 against defense and aerospace targets.
And it gets better:
• Windows kernel exploitation
• FudModule rootkit
• ML-KEM post-quantum key exchange
• DLL sideloading
• In-memory malware
• Microsoft Graph + OneDrive C2
• Hijacked infrastructure
• Security telemetry disruption
Exploit devs and reverse engineers: study the kernel path.
Malware analysts: study the implant chain.
Red teamers: study the tradecraft.
Blue teams + detection engineers: figure out what telemetry is still trustworthy after the attacker reaches Ring 0.
Threat intel: this is Lazarus operationalizing serious Windows kernel research in the wild.
Fresh technical deep dive:
https://cyllex.io/blog/posts/lazarus-ring-0-cve-2026-68820.html?v=1
#0day#WindowsKernel#MalwareAnalysis#ThreatIntel
Post summary
The post declares CVE‑2026‑68820, a use‑after‑free in Windows AFD.sys, is being actively exploited by the Lazarus group, details a sophisticated rootkit chain, and references a deep‑dive technical article.
0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector:
💥LPE vulnerability in Microsoft’s Afd.sys driver (CVE-2026-68820)
🧰New tools, including #Troy backdoor
🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure
Read More :
https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/ https://t.co/MIGKtH6FlM
Post summary
The post announces that Lazarus used the CVE‑2026‑68820 LPE vulnerability in a real‑world campaign against the defense sector, deploying new backdoor tools and leveraging compromised Roundcube servers.
🛑 398 fixes. One exploited Windows zero-day. Four unauthenticated 9.8 RCEs.
Microsoft’s August Patch Tuesday fixes CVE-2026-68820, which can elevate an attacker with existing code execution to SYSTEM.
It also closes the RCE half of a SharePoint exploit chain.
Here’s what to patch first ➝ https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html
Post summary
Microsoft’s August Patch Tuesday addresses 398 vulnerabilities, including CVE‑2026‑68820 which can elevate code execution to SYSTEM, and it also closes the RCE component of a SharePoint exploit chain. The update comes with patch instructions and a warning to prioritize the fixes.
🚨 WINDOWS ZERO-DAY ALERT: Lazarus exploited an unpatched flaw in AFD.sys (CVE-2026-68820) to get SYSTEM access and deploy FudModule v3.1 undetected. Patched Aug 11 — were you already hit?👇
0-Day Details: https://cybersecuritynews.com/windows-afd-sys-zero-day-exploited/
#cybersecuritynews https://t.co/CcKBhBLXMp
Post summary
The post reports that Lazarus exploited the unpatched AFD.sys flaw (CVE-2026-68820) to gain SYSTEM access and deploy FudModule v3.1, with the vulnerability patched on Aug 11.
🚨 Lazarus-linked attacks exploit a Windows zero-day for SYSTEM access.
Dream Job lures defense and aerospace targets with fake recruiter messages. One chain exploits CVE-2026-68820 for privilege escalation; another uses a trojanized PDF viewer to load the new Troy backdoor.
See how the attacks work: https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
Post summary
Lazarus-linked actors are actively exploiting CVE-2026-68820 to gain SYSTEM-level access in attacks against defense and aerospace targets, deploying a new backdoor via a trojanized PDF viewer.
Active in-the-wild zero-day and privilege escalation attacks targeting the Windows kernel and core OS execution layer center on several key vulnerabilities added to CISA's Known Exploited Vulnerabilities (KEV) catalog:
CVE-2026-68820 (Windows Kernel Ancillary Function Driver - afd.sys): A high-severity use-after-free race condition in the kernel-mode socket driver. Attackers already possessing low-privilege execution run crafted applications to trigger the condition and elevate privileges to NT AUTHORITY\SYSTEM without user interaction. Threat actors frequently chain afd.sys zero-days with remote code execution (RCE) vectors or browser sandbox escapes.
CVE-2026-85880 (Windows Advanced Local Procedure Call - ALPC): A heap-based buffer overflow in the ALPC communication mechanism. Confirmed exploited in the wild, this flaw allows an attacker executing code inside a sandboxed, low-privilege AppContainer to escape isolation and gain SYSTEM privileges locally.
CVE-2026-81963 (Windows Update Stack Link Following): An improper link resolution vulnerability exploited in targeted zero-day attacks to force the update subsystem to follow malicious symbolic links and overwrite protected system components, granting SYSTEM access.
Common Attack Pattern
Because these are Local Privilege Escalation (LPE) vulnerabilities, threat actors do not use them for initial access across the network. Instead, they appear as Stage 2 in exploit chains:
Initial Compromise: Phishing payload, malicious document, or browser drive-by execution within a sandboxed context.
Kernel Exploitation: Triggering the driver or ALPC flaw to bypass Kernel Patch Protection (PatchGuard) or Virtualization-Based Security (VBS) boundaries.
Payload Delivery: Disabling EDR agents directly from kernel space (Bring Your Own Vulnerable Driver/direct kernel write techniques) and dumping LSASS credentials for lateral movement.
Several in‑the‑wild Windows kernel LPE zero‑days are now on CISA’s KEV: CVE‑2026‑68820 (afd.sys), CVE‑2026‑85880 (ALPC) and CVE‑2026‑81963 (update link‑follow). Attackers use these as stage‑2 after initial compromise to escape sandboxes, gain SYSTEM, disable EDR and dump creds.
#WindowsSecurity#CVE202668820, #AfdSys, #ZeroDay, #KernelExploit, #PrivilegeEscalation, #EoP, #WindowsSecurity, #ThreatIntel, #OperationDreamJob, #FudModule, #Rootkit, #APT, #CyberSecurity, #InfoSec, #PatchTuesday, #CISA, #KEV, #BlueTeam, #VulnerabilityManagement#ShieldCrash
Post summary
The text documents multiple Windows kernel vulnerabilities that are actively exploited in the wild as stage‑2 privilege‑escalation tools, detailing technical flaws and typical attack chains.
Check Point researchers look at the latest variant of the Operation Dream Job campaign where the threat actor exploited CVE-2026-68820, a 0day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of Lazarus’s kernel-mode rootkit FudModule https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/ https://t.co/fAJKINtII2
Post summary
The post reports that threat actors actively exploited CVE‑2026‑68820, a 0‑day flaw in Microsoft’s AFD.sys driver, to deploy a kernel‑mode rootkit, confirming real‑world exploitation with no mention of patches or PoC details.
🚨 Hoy en ciberseguridad México:
🔴 Microsoft Patch Tuesday agosto — 400+ vulnerabilidades.
Una ya está siendo explotada activamente por actores norcoreanos.
CVE-2026-68820 — zero-day en el driver de sockets de Windows.
Permite escalar a SYSTEM desde una cuenta con privilegios bajos.
Si tienes Windows sin parchear — ya entraron o están intentando entrar.
🔴 Microsoft Teams — CVSS 10.0. Elevación de privilegios sin autenticación.
La herramienta de trabajo de prácticamente todo el gobierno y empresas mexicanas.
🔴 México tiene un déficit de 77,000 especialistas en ciberseguridad.
400+ vulnerabilidades nuevas este mes.
77,000 personas que no existen para responderlas.
Y un Patch Tuesday que no espera a nadie.
📎 Help Net Security / Infobae / MSRC — 12/08/2026
http://helpnetsecurity.com/2026/08/12/august-2026-patch-tuesday-cve-2026-68820/
Post summary
The post announces that CVE‑2026‑68820, a zero‑day escalating to SYSTEM, is being actively exploited by North Korean actors and warns unpatched Windows systems.
📢El #ColCERT emite una nueva #AlertaDeSeguridad sobre Operation Dream Job, una campaña que incorpora la explotación de la vulnerabilidad CVE-2026-68820 en Windows.
👉Consulta la alerta y fortalece las medidas de prevención:
https://www.colcert.gov.co/800/w3-article-440371.html https://t.co/eOB56r4FdR
Post summary
ColCERT’s alert highlights that the Operation Dream Job campaign actively exploits CVE-2026-68820 on Windows, underscoring current in‑the‑wild usage.
Operation Dream Job
#Lazarus exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit.
https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Lazarus also used CVE-2025-49113 to exploit vulnerable Roundcube webmail servers. The compromised servers were infected with RelayShell, a PHP webshell that repurposes compromised web servers as relay nodes within the attacker’s command-and-control infrastructure.
Post summary
Lazarus Group is actively exploiting CVE‑2026‑68820 in Microsoft AFD.sys to deploy the kernel‑mode rootkit FudModule and CVE‑2025‑49113 to compromise Roundcube servers, installing the RelayShell webshell for command‑and‑control.
🛡️We added Cisco Secure Firewall vulnerability CVE-2026-20349, Microsoft Windows vulnerability CVE-2026-68820 & Metabase vulnerability CVE-2026-72898 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity https://t.co/iahRvhwOoT
Post summary
The tweet announces that three CVEs (Cisco Secure Firewall, Microsoft Windows, Metabase) have been added to the DHS KEV Catalog and directs readers to a link to apply mitigations, indicating these vulnerabilities are actively exploited or pose a high risk.
미국 국토안보부 산하 사이버보안·인프라보안국(CISA)이 12일 마이크로소프트와 함께 윈도우 운영체제의 보안 결함(CVE-2026-68820)이 실제 공격에 악용되고 있다고 확인했습니다.
https://www.voakorea.com/a/cisa-windows-vulnerability-north-korean-attack-2026-081326/8186032.html https://t.co/KbqumrOucb
Post summary
CISA reports that Microsoft Windows CVE‑2026‑68820 is currently being exploited in real attacks.
يصل المهاجم إلى جهاز ويندوز بصلاحيات مستخدم عادي…
ثم يستغل خطأً داخل النواة ليصبح NT AUTHORITY\SYSTEM، أعلى سلطة في النظام، ويفتح الطريق لتعطيل رؤية أدوات الحماية. هذا ليس سيناريو نظريًا؛ بل ثغرة يوم صفر استغلتها Lazarus فعليًا: CVE-2026-68820.
وراء كل اختراق… قصة 👇
لكن انتبه: الثغرة لم تُدخل المهاجم إلى الجهاز عن بُعد. في Operation Dream Job، بدأت السلسلة بعرض وظيفة مزيف وملفات أو عارضات PDF ملغّمة. وبعد تشغيل البرمجية الخبيثة وحصولها على موطئ قدم محلي، جاء دور الثغرة لرفع الصلاحيات.
نقطة التحول كانت afd.sys، وهو برنامج تشغيل داخل نواة ويندوز يعالج عمليات WinSock. الثغرة من نوع Use-After-Free: تُحرر مساحة في ذاكرة النواة، لكن مسارًا آخر يستمر في استخدامها. وهنا يتحول خطأ في إدارة الذاكرة إلى فرصة للسيطرة داخل النواة.
كيف يحدث ذلك؟ تتعامل عدة خيوط مع حالة socket في الوقت نفسه دون تزامن كافٍ، فتقع Race Condition. وإذا نجح المهاجم في استغلالها، يحصل على Kernel Read/Write؛ أي قدرة القراءة والكتابة داخل ذاكرة النواة، ثم يرتقي إلى SYSTEM. أما التفاصيل الكاملة للاستغلال فلم ينشرها الباحثون.
الوصول إلى SYSTEM لم يكن النهاية. استُخدمت الصلاحيات لتشغيل FudModule، وهو Rootkit على مستوى النواة، وحقن حمولة داخل عملية SYSTEM وتعطيل رؤية EDR. لذلك كانت ثغرة مصنفة High بدرجة 7.0 شديدة الخطورة عمليًا: السياق الهجومي أخطر من الرقم.
الدفاع يبدأ من كسر السلسلة:
• تثبيت تحديثات Microsoft الصادرة في 11 أغسطس 2026.
• حصر الأنظمة غير المحدثة، خصوصًا الحرجة.
• رصد الانتقال المفاجئ من مستخدم عادي إلى SYSTEM.
• منع البرامج وعارضات PDF غير الموثوقة.
EDR وApplication Control لا يعوضان التصحيح.
أدرجت CISA الثغرة ضمن KEV لأنها مستغلة فعليًا.
Microsoft MSRC:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820
Check Point Research:
https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
CISA KEV:
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-68820
لا أنقل الخبر فقط… أشرح ما وراءه.
Post summary
The post confirms CVE-2026-68820, a high‑severity Windows kernel use‑after‑free flaw, was actively exploited by Lazarus in the wild, provides technical details and mitigation advice, and cites official patch and CISA KEV references.
The post announces CVE-2026-68820 and states that exploitation has been confirmed by Microsoft, but provides no PoC, tool, patch information, or technical details.
🚨 مهم جداً
مجموعة Lazarus التابعه لكوريا الشمالية تستغل حالياً ثغره CVE-2026-68820 الي تم اصلاحها في تحديث هذا الاسبوع من مايكروسفت
الثغرة في AFD.sys وتسمح للمهاجم تصعيد صلاحياته الى SYSTEM
التفاصيل: 🧵👇 https://t.co/4522nrlN0w
Post summary
The tweet reports that the Lazarus group is actively exploiting CVE-2026-68820, a privilege‑elevation flaw in AFD.sys that was patched by Microsoft this week.
Check Point Research documented Lazarus’ Operation Dream Job campaign evolving with a zero-day AFD.sys exploit (CVE-2026-68820), trojanized PDF viewers, RelayShell C2 infrastructure, and the new Troy backdoor. https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Post summary
Check Point Research announced a new zero‑day vulnerability CVE‑2026‑68820 in AFD.sys tied to Lazarus Operation Dream Job, detailing malware components, but did not provide PoC, exploit code, or patch information.
North Korea used servers vulnerable to a bug we found as C2 in its latest campaign targeting the defence, aerospace, and aviation sectors.
Check Point's report last week: Lazarus exploited a Windows kernel zero-day, CVE-2026-68820 in afd.sys, since at least early July against defense, aerospace and aviation targets in France, Germany, Brazil and India.
The campaign ran two parallel infection chains. One used signed-binary DLL sideloading to execute MISTPEN in memory. The other used a trojanized PDF viewer to deploy a new backdoor, Troy. Both could escalate to SYSTEM through CVE-2026-68820, followed by a new FudModule build designed to disable EDR visibility. MISTPEN ultimately deployed ForestTiger for long-term access.
Microsoft patched the zero-day on 11 August.
Much of the C2 infrastructure wasn't theirs.
Check Point found compromised Roundcube, WordPress and PrestaShop servers being used as relay infrastructure. It assesses that Lazarus likely authenticated to vulnerable Roundcube servers using leaked credentials, exploited CVE-2025-49113, and planted RelayShell.
The researchers identified at least 17 likely relay nodes.
One compromised organization headquartered in France was then used to spear-phish targets worldwide - borrowing a legitimate organization's infrastructure and reputation to make the messages more credible.
CVE-2025-49113 is ours.
Our co-founder @k_firsov discovered and reported it in May 2025: authenticated RCE via PHP object deserialization, CVSS 9.9, sitting in the Roundcube codebase for more than a decade.
Roundcube patched it on 1 June 2025.
Attackers diffed and weaponized the vulnerability within 48 hours of the patch becoming available, with a working exploit offered for sale days later. We published the full technical breakdown to give defenders parity.
CISA added CVE-2025-49113 to its Known Exploited Vulnerabilities catalog in February 2026, with a 13 March remediation deadline for covered US federal agencies.
And Lazarus was still exploiting unpatched Roundcube servers in this campaign.
We know the tradecraft because we spend our year on the other end of it.
Lazarus is heavily involved in cryptocurrency theft, and we run continuous adversarial simulation against exchanges and protocols that sit high on the DPRK targeting list.
The objectives differ, but the tradecraft overlaps: recruitment lures, signed-binary sideloading, credential theft, and kernel-level evasion.
Theft there. Espionage here.
If you build aircraft, satellites, drones, avionics, sensors or related defense technology, your engineers fit the targeting profile.
And your internet-facing Roundcube, WordPress or PrestaShop infrastructure can become someone else's C2 if it isn't secured and patched.
We find the bugs that might end up in campaigns like this one.
We also run the campaign against our own clients first, on purpose, with a scope document.
Our research: https://lnkd.in/dzS-RYcz
Post summary
The post reports that the Lazarus group used CVE‑2026‑68820 and CVE‑2025‑49113 in real attacks against defense sectors, includes PoC and exploit details, and notes recent patches while confirming active exploitation.
North Korean hackers already used this zero-day before it was patched.
Cyber Pulse 🛡️🦅
Microsoft’s August Patch Tuesday fixed a Windows kernel zero-day CVE-2026-68820 that Lazarus Group had already been exploiting in the wild.
The flaw allowed attackers to gain SYSTEM privileges.
If you haven’t applied the latest Windows updates, do it now.
How quickly does your organisation usually roll out critical Microsoft patches?
#CyberSecurity#ZeroDay#CurrentThreats
Post summary
The post highlights that the CVE‑2026‑68820 Windows kernel zero‑day was actively exploited by Lazarus Group and has been patched in Microsoft’s August Patch Tuesday.
🚨 Lazarus explota zero-day en Windows (CVE-2026-68820)
Falsa oferta de trabajo → elevación a SYSTEM vía AFD.sys → rootkit FudModule + backdoor Troy. Ya hay targets en defensa (incluye Brasil).
Parche de Patch Tuesday YA. No esperes.
#ZeroDay#Lazarus#Windows https://t.co/liRWPe3Oh2
Post summary
A zero‑day CVE‑2026‑68820 on Windows is being exploited by Lazarus with AFD.sys privilege escalation and rootkit/backdoor components, targeting defense sectors, but a Patch Tuesday fix is already available.
Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.
#Lazarus#ZeroDay#CVE202668820#OperationDreamJob#Cybersecurity#DPRK#FudModule#DefenseSector
http://securityonline.info/lazarus-zero-day-dream-job/
Post summary
The post reports that Lazarus actively exploited the Windows zero‑day CVE‑2026‑68820 in Operation Dream Job, targeting defense firms with fake job offers and a backdoor. No technical details, PoC, or mitigation are provided.