CVE Tools
Back to feed
Exploited in the wild Windows Lazarus patch-tuesday afd.sys Microsoft

Microsoft выпустила патчи более чем для 400 уязвимостей

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Microsoft released its August security updates addressing 421 vulnerabilities, three of which were classified as zero-days. Most notably, CVE-2026-68820, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys), has been actively exploited by the North Korean threat group Lazarus.

Researchers attribute this exploitation to the "Operation Dream Job" campaign, where attackers targeted defense organizations in Europe and India using fake job offers from companies like Lockheed Martin and Enveil. Upon compromising systems via a modified PDF reader called SecurityPDF and implanting the Troy backdoor, threat actors leveraged CVE-2026-68820 to escalate privileges to SYSTEM level and deploy the FudModule rootkit.