
Patch Tuesday hits 421 fixes as Lazarus exploits a new zero-day
Microsoft’s August Patch Tuesday patches 421 CVEs, including CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock that North Korea’s Lazarus Group allegedly weaponized as a zero-day in June. Analysts link the campaigns to the Dream Job operation, which uses fake defense-industry job sites and a Trojanized PDF viewer called SecurityPDF delivered via phishing to install the backdoor Troy. Other notable fixes include CVE-2026-62832 (privilege escalation via loading another user’s registry hive) and CVE-2026-62893 (Windows Deployment Services TFTP remote code execution), among others highlighted by researchers and ZDI.



