Urgent.News

What's breaking now, across thousands of outlets.

Tech

Lazarus exploits Windows zero-day in defence attacks

North Korea-linked hackers exploited a previously unknown Windows vulnerability to gain the highest level of system privileges while targeting defence, aerospace and aviation organisations across several countries. The flaw, tracked as CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock, known as AFD. sys. Microsoft patched the vulnerability on August 11 after it was found…

North Korean hackers exploited a newly discovered Windows vulnerability to gain complete control over high-level systems in defense, aerospace, and aviation organizations worldwide. The flaw, labeled CVE-2026-68820, targets the Windows Ancillary Function Driver for WinSock, AFD.sys. Microsoft released a patch on August 11, addressing the vulnerability discovered during Operation Dream Job, a cyber-espionage campaign linked to the Lazarus Group.

This campaign targeted France, Germany, Brazil, and India, focusing on companies related to military technology, aviation, surveillance systems, drones, and robotics. The vulnerability had been exploited since early July, not just two months, as initially reported. CVE-2026-68820 is a use-after-free vulnerability, caused by a race condition in AFD.sys, a kernel component managing Windows network sockets.

Once an attacker has code running on a compromised computer, they can exploit this weakness to elevate their privileges to SYSTEM, effectively controlling the machine. The vulnerability was deemed significant, with a CVSS severity score of 7.0, and was the only one confirmed as actively exploited during the August security release.

The Lazarus Group employed social engineering techniques, posing as recruiters with enticing job offers from prominent companies. Victims were directed to malicious files or software disguised as legitimate tools for viewing job-related PDF documents. One infection chain employed a digitally signed PDF viewer, malicious DLL, and encrypted payload through DLL sideloading.

Another chain used SecurityPDF, a modified application based on the legitimate open-source MuPDF framework. This trojanized viewer was distributed through at least three websites, gaining prominent search results. SecurityPDF was designed to recognize specially prepared files masquerading as ordinary PDFs. Upon opening, it extracted and launched an encrypted executable payload, loading a backdoor named Troy.

This 64-bit malware, supporting 17 commands, allows attackers extensive control of infected computers. The attackers also utilized MISTPEN as an in-memory downloader, enabling communications through Microsoft Graph and OneDrive to blend malicious activity with legitimate network traffic. The Lazarus Group integrated CVE-2026-68820 into an updated version of the FudModule kernel rootkit, allowing the rootkit to operate with SYSTEM privileges and interfere with security monitoring.

Targeting newer Windows builds, the rootkit aimed to tamper with Windows Smart App Control and suppress security products. To make command-and-control infrastructure harder to identify, the attackers exploited compromised Roundcube webmail systems, infecting them with a PHP web shell named RelayShell.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thearabianpost.com →

More in Tech

The Best Model Isn’t Enough: Harnesses, Context, and Better Prompts

We used to believe that a better model automatically meant better results. And that’s true to some degree, but the reality is that most people aren’t using all the available tools and techniques to…

  • Superior AI models alone don't guarantee superior results
  • Harness and context management are critical for maximizing model potential
  • Prompt engineering techniques can improve model outcomes

Google raises Pixel prices as AI takes centre stage

Google has unveiled its Pixel 11 smartphone range with higher starting prices, a new Tensor G6 processor and deeper Gemini integration, placing artificial intelligence at the centre of its latest…

  • Pixel 11 starts at $899, Pro at $1,099, Pro XL at $1,299
  • Tensor G6 chip touted as fastest and most powerful smartphone processor
  • Gemini AI integrates into devices for proactive user assistance

More from Wednesday 12 August →