Tag

Cve 2026 68820

All articles tagged with #cve 2026 68820

Lazarus Exploits Windows Zero-Day to Hit Defense Firms, Unleashing Rootkit and Backdoors
technology1 month ago

Lazarus Exploits Windows Zero-Day to Hit Defense Firms, Unleashing Rootkit and Backdoors

North Korean Lazarus hackers used a Windows use-after-free vulnerability (CVE-2026-68820) in AFD.sys to elevate privileges and deploy a kernel-mode rootkit (FudModule) plus a new backdoor (Troy) as part of the Operation Dream Job campaign targeting defense, aerospace, and aviation firms in Europe, India, and beyond, including attacks via compromised Roundcube instances and a RelayShell web shell; Microsoft patched the flaw as actively exploited, signaling a continuing, globally distributed intrusion effort.

Patch Tuesday hits 421 fixes as Lazarus exploits a new zero-day
cybersecurity1 month ago

Patch Tuesday hits 421 fixes as Lazarus exploits a new zero-day

Microsoft’s August Patch Tuesday patches 421 CVEs, including CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock that North Korea’s Lazarus Group allegedly weaponized as a zero-day in June. Analysts link the campaigns to the Dream Job operation, which uses fake defense-industry job sites and a Trojanized PDF viewer called SecurityPDF delivered via phishing to install the backdoor Troy. Other notable fixes include CVE-2026-62832 (privilege escalation via loading another user’s registry hive) and CVE-2026-62893 (Windows Deployment Services TFTP remote code execution), among others highlighted by researchers and ZDI.

security1 month ago

Microsoft Patch Tuesday Deluge: 398 Flaws Fixed, Zero-Day in afd.sys Exposed

Microsoft released a massive Patch Tuesday, fixing 398 vulnerabilities across Windows and related software, including a zero-day in afd.sys (CVE-2026-68820) and two other publicly disclosed flaws; 42 fixes are critical. AI aided vulnerability discovery, but patching remains heavily human-driven and requires testing. Users should back up data and deploy updates cautiously, as large update bundles may take time to stabilize.