Microsoft released patches for 421 vulnerabilities yesterday, and North Korea's Lazarus Group had already weaponized one of them. The exploited flaw, CVE-2026-68820, is a use-after-free bug in the Windows Ancillary Function Driver for WinSock that grants attackers SYSTEM-level privileges without user interaction.

Check Point researchers Moshe Marelus and David Driker discovered and reported the vulnerability. Their threat intelligence team first observed Lazarus exploiting it in early June, two months before Microsoft could ship a fix.
How Lazarus exploited the zero-day
The vulnerability lets a locally authenticated attacker trigger a race condition by running a specially crafted application. At a high level, the exploit abuses how afd.sys handles socket creation when multiple threads access it simultaneously.
Lazarus deployed a new version of FudModule, its kernel-mode rootkit, through the exploit. Check Point withheld full technical details since the patch only shipped yesterday.
"We are familiar with one successful implementation of the CVE, but we assume it was used widely in the campaign," Sergey Shykevich, Check Point's director of threat intelligence, told The Register.
Operation Dream Job targets defense sector
The attacks belong to Operation Dream Job, a Lazarus campaign running since 2020. The playbook: social engineering with fake job offers for high-profile positions, then tricking victims into opening malware-laced documents or clicking malicious links.
This wave focused on defense organizations in Europe and India. Attackers impersonated Lockheed Martin and privacy-tech firm Enveil, creating at least three fake Enveil websites. Some even ranked as top search results, making phishing detection harder.
"The threat actor expanded its delivery method by leveraging impersonation websites and search engine optimization techniques to distribute the trojanized applications, increasing its credibility and helping it evade some phishing-based detections," Check Point researchers wrote.
The attackers distributed a modified PDF viewer called SecurityPDF that executes malicious payloads embedded in attacker-crafted PDF files. Opening these PDFs triggers a previously unknown backdoor Check Point named Troy.
The other 420 bugs
One other CVE deserves immediate attention. CVE-2026-62832, an elevation-of-privilege flaw, is publicly known and Microsoft rates exploitation as "more likely."
An authenticated attacker with credentials for another local account can run a specially crafted application to load another user's registry hive. Success grants access to that user's data and administrator privileges. No user interaction required.
The August count of 421 CVEs sits about 200 below last month's record-setting 622. Redmond and security researchers expect these higher numbers to become normal as AI tools accelerate vulnerability discovery and patching.
Logicity's Take
The two-month gap between Lazarus's first exploitation in June and Microsoft's patch matters for every IT team. Attackers using SEO to rank fake employer sites above real ones signals a shift in phishing tactics that email security tools alone won't catch. Defense-sector organizations should assume they were targeted and hunt for indicators of compromise Check Point will likely publish shortly.
What IT teams should do now
Patch CVE-2026-68820 and CVE-2026-62832 first. Both require local authentication, which limits but does not eliminate risk. If Lazarus already has a foothold in your network, they have exactly the access these bugs need.
Organizations in defense, aerospace, or adjacent sectors should review recent PDF file activity and look for SecurityPDF or the Troy backdoor. Check Point's blog includes indicators of compromise.
This also means revisiting how your teams verify job outreach. When fake employer sites rank higher than real ones, security awareness training built around "check the URL" needs updating.
Need Help Implementing This?
If your team needs guidance on prioritizing these patches or hunting for Lazarus indicators in your environment, reach out to Logicity's security advisory partners for a rapid assessment.
Source: www.theregister.com
Huma Shazia
Senior AI & Tech Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.






