CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
ID: 99ea1c74-a8e0-5a7f-a87d-29267a854c91
STIX ID: report--99ea1c74-a8e0-5a7f-a87d-29267a854c91
Feed Name: The Record from Recorded Future News
Threat Score
CISA and Microsoft confirmed that CVE-2026-68820, a Winsock kernel-related Windows zero-day, is being exploited in the wild by North Korea’s Lazarus Group as part of the long-running Operation “Dream Job” campaign: attackers use malicious PDF job-offer lures to gain a low-privileged foothold, then deploy the Winsock exploit to escalate privileges and install a persistent backdoor, prompting a federal patch directive with a required restart and no workaround.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
