Lazarus exploits Windows zero-day in defence attacks
North Korea-linked hackers exploited a previously unknown Windows vulnerability to gain the highest level of system privileges while targeting defence, aerospace and aviation organisations across several countries. The flaw, tracked as CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock, known as AFD. sys. Microsoft patched the vulnerability on August 11 after it was found…
Arabian Post reports that North Korean hackers, associated with the Lazarus Group, have exploited a previously unknown Windows vulnerability to gain high-level system privileges in a targeted cyber attack. The flaw, identified as CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock, known as AFD.sys. Microsoft patched the vulnerability on August 11, after it was found to be actively exploited as part of Operation Dream Job, a long-running cyber-espionage campaign.
The attackers primarily targeted organizations in France, Germany, Brazil, and India, focusing on companies involved in military technology, aviation, surveillance systems, drones, and robotics. The vulnerability, a use-after-free flaw caused by a race condition in AFD.sys, allows an attacker with existing code on a targeted computer to elevate privileges to SYSTEM, granting full control of the machine.
Microsoft classified the flaw as important, assigning it a CVSS severity score of 7.0. The Lazarus Group's operation combined the privilege-escalation flaw with social engineering techniques, including posing as recruiters and distributing malicious files or software disguised as legitimate tools for viewing job-related PDF documents.
Brief written by urgent.news from Arabian Post's own syndicated text. Machine-written — it may contain errors, so check the original before relying on it.