Coming soon The Briev app is almost here. Leave your email and be first in on launch day.

Briev
Live
Technology
UNDERREPORTED

Microsoft patches 421 flaws as North Korean Lazarus Group weaponizes a new zero-day

Microsoft’s August Patch Tuesday addressed 421 vulnerabilities, and researchers say North Korea’s Lazarus Group exploited one of them, CVE-2026-68820, as a zero-day in June.

Microsoft’s August security update fixed 421 vulnerabilities, roughly 200 fewer than the July release, a trend analysts attribute to AI-enhanced vulnerability discovery. Among the patches, CVE-2026-68820 - a use-after-free bug in the Windows Ancillary Function Driver for WinSock - was reportedly exploited as a zero-day by North Korea’s Lazarus Group in early June. Check Point’s Moshe Marelus and David Driker discovered the flaw, and threat-intel director Sergey Shykevich linked it to the group’s long-running Operation Dream Job, which lures job seekers with fake offers and delivers a trojanised PDF viewer called SecurityPDF that drops a new backdoor named Troy.

The attackers used the vulnerability to install an updated version of their kernel-mode rootkit, FudModule. Microsoft also flagged CVE-2026-62832, an elevation-of-privilege issue, as highly exploitable. Trend Micro’s Zero Day Initiative highlighted five additional critical bugs, including a remote-code-execution flaw in Windows Deployment Services and an Exchange privilege-escalation bug demonstrated at the Pwn2Own contest. Experts urge rapid deployment of the patches to mitigate the risk of further state-backed attacks.

Why it matters

State-sponsored hackers are already exploiting fresh Windows flaws, making prompt patching essential for organisations.

In this story

Microsoft Patch TuesdayCVE-2026-68820Lazarus Groupzero-day exploitOperation Dream JobAI-assisted vulnerabilitySecurityPDFTroy backdoor