CVE Tools
Back to feed
Exploited in the wild Windows AFD.sys Lazarus Group nation-state Microsoft phishing

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

Check Point has reported that North Korea's Lazarus Group is actively exploiting a newly patched Windows zero-day vulnerability to compromise systems within the global defense sector. The attacks leverage a use-after-free flaw in the Ancillary Function Driver for WinSock (afd.sys), identified as CVE-2026-68820, to achieve System-level privileges.

Microsoft addressed this critical race condition during its August 2026 Patch Tuesday cycle, and CISA has since added the identifier to its Known Exploited Vulnerabilities catalog. The campaign, dubbed Operation Dream Job, utilizes social engineering tactics involving fake recruitment offers to deliver malware such as Mistpen and ForestTiger.