Microsoft patches 421 flaws as North Korean Lazarus Group weaponizes a new zero-day
Microsoft’s August Patch Tuesday addressed 421 vulnerabilities, and researchers say North Korea’s Lazarus Group exploited one of them, CVE-2026-68820, as a zero-day in June.
Microsoft’s August security update fixed 421 vulnerabilities, roughly 200 fewer than the July release, a trend analysts attribute to AI-enhanced vulnerability discovery. Among the patches, CVE-2026-68820 - a use-after-free bug in the Windows Ancillary Function Driver for WinSock - was reportedly exploited as a zero-day by North Korea’s Lazarus Group in early June. Check Point’s Moshe Marelus and David Driker discovered the flaw, and threat-intel director Sergey Shykevich linked it to the group’s long-running Operation Dream Job, which lures job seekers with fake offers and delivers a trojanised PDF viewer called SecurityPDF that drops a new backdoor named Troy.
The attackers used the vulnerability to install an updated version of their kernel-mode rootkit, FudModule. Microsoft also flagged CVE-2026-62832, an elevation-of-privilege issue, as highly exploitable. Trend Micro’s Zero Day Initiative highlighted five additional critical bugs, including a remote-code-execution flaw in Windows Deployment Services and an Exchange privilege-escalation bug demonstrated at the Pwn2Own contest. Experts urge rapid deployment of the patches to mitigate the risk of further state-backed attacks.
Why it matters
State-sponsored hackers are already exploiting fresh Windows flaws, making prompt patching essential for organisations.
In this story