North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026–68820) to target defense-sector companies as part of the Operation Dream Job campaign.
Microsoft addressed the flaw in this month’s Patch Tuesday security updates, marking it as actively exploited in the wild. Researchers found that the Lazarus threat group has been leveraging it since early July.
Microsoft says that the vulnerability is a “use-after-free in Windows Ancillary Function Driver for WinSock (AFD.sys)” that allows an attacker to increase their local privileges.
