Skip to content
Back to Guavy Wire
Stocks

Lazarus Exploits Zero-Day Flaw in Microsoft's August Patch Tuesday

Instruments
MSFT
Share

Microsoft has released its August 2026 Patch Tuesday security updates, addressing over 400 vulnerabilities across Windows and other supported products.

The most urgent vulnerability is an elevation-of-privilege flaw in the Windows Ancillary Function Driver for WinSock, tracked as CVE-2026-68820. Microsoft confirmed that attackers had exploited the vulnerability in the wild, while Check Point attributed the observed attacks to the North Korean state-sponsored group widely known as Lazarus.

The August release also fixes two vulnerabilities that were publicly known before patches became available: a Windows User Profile Service flaw matching the previously disclosed 'LegacyHive' technique and a tampering vulnerability in the Windows Container Isolation file-system filter driver.

Microsoft credited Check Point researchers Moshe Marelus and David Driker with discovering and reporting CVE-2026-68820, which was used by Lazarus to deploy a newly observed version of FudModule, a kernel-mode rootkit linked to the group.

More on Stocks

Disclaimer: Guavy is a data and market intelligence provider, not an investment adviser. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc