421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one
Sysadmins, welcome to your new norm
In Microsoft's Patch Tuesday release this month, there were 421 bugs addressed, a significant number that is likely the new norm due to AI-assisted vulnerability disclosures and fixes. North Korea's Lazarus Group, along with potentially other threat actors, discovered and exploited one of these flaws as a zero-day vulnerability in early June.
The bug, CVE-2026-68820, is a use-after-free issue in the Windows Ancillary Function Driver for WinSock. Upon successful exploitation, an attacker could execute code with SYSTEM-level privileges, all without requiring user interaction.
Microsoft credited Check Point researchers Moshe Marelus and David Driker for their discovery and reporting of CVE-2026-68820. According to Sergey Shykevich, Check Point's threat intelligence lead, his team first observed attackers attacking this CVE at the beginning of June. This campaign, known as Operation Dream Job, targets organizations worldwide, particularly those in the defense sector, and is attributed to North Korea's Lazarus Group, a government-sponsored hacking collective known for cryptocurrency theft, extortion, and IT worker scams.
Lazarus' Dream Job campaigns involve social engineering tactics to lure victims into clicking on malicious links or opening malware-laden documents. In this particular campaign, the attackers impersonated high-profile companies like Lockheed Martin and Enveil, creating multiple fake websites and even ranking among the top search results.
They then distributed a modified PDF viewer called SecurityPDF, which executes malicious payloads when opened, leading to the deployment of a new version of FudModule, Lazarus' kernel-mode rootkit.
Microsoft has also identified five other notable vulnerabilities in the August patch cycle. One of these, CVE-2026-62832, is an elevation-of-privilege flaw that allows an authenticated attacker with credentials for another local account to access or modify another user's data and gain administrator privileges. Another, CVE-2026-68820, is a critical zero-day that the Lazarus Group exploited for their recent campaign.
Lastly, CVE-2026-62911, discovered through ZDI's bug reporting program and demonstrated at ZDI's Pwn2Own contest in Berlin, allows an attacker to take over Exchange mailboxes through an authentication bypass.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.