Urgent.News

What's breaking now, across thousands of outlets.

Tech

421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one

Sysadmins, welcome to your new norm

421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one

Microsoft released 421 patches during Patch Tuesday, though fewer than a month prior. North Korea's Lazarus Group, along with other threat actors, exploited one of these vulnerabilities as a zero-day attack in early June. The bug, labeled CVE-2026-68820, is a use-after-free error in the Windows Ancillary Function Driver for WinSock.

This flaw allows a local attacker to execute code with SYSTEM-level privileges without user interaction. Check Point researchers identified the vulnerability and reported it to Microsoft. The Lazarus Group is known for various cyber attacks, including the Sony Pictures Entertainment hack in 2014 and the WannaCry ransomware outbreak in 2017.

In June, the group targeted defense sector organizations in Europe and India with phishing emails impersonating well-known companies. The attacks involved distributing modified PDF viewers designed to execute malicious payloads when opened. This campaign exploited the CVE-2026-68820 zero-day vulnerability to deploy a new version of FudModule, a kernel-mode rootkit.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Tuesday 11 August →