logo

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

ID: 99ea1c74-a8e0-5a7f-a87d-29267a854c91

STIX ID: report--99ea1c74-a8e0-5a7f-a87d-29267a854c91

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2026-08-12

Date Updated: 2026-08-12

...
...

CISA and Microsoft confirmed that CVE-2026-68820, a Winsock kernel-related Windows zero-day, is being exploited in the wild by North Korea’s Lazarus Group as part of the long-running Operation “Dream Job” campaign: attackers use malicious PDF job-offer lures to gain a low-privileged foothold, then deploy the Winsock exploit to escalate privileges and install a persistent backdoor, prompting a federal patch directive with a required restart and no workaround.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.