Lazarus Exploits Zero-Day Flaw in Microsoft's August Patch Tuesday
Microsoft has released its August 2026 Patch Tuesday security updates, addressing over 400 vulnerabilities across Windows and other supported products.
The most urgent vulnerability is an elevation-of-privilege flaw in the Windows Ancillary Function Driver for WinSock, tracked as CVE-2026-68820. Microsoft confirmed that attackers had exploited the vulnerability in the wild, while Check Point attributed the observed attacks to the North Korean state-sponsored group widely known as Lazarus.
The August release also fixes two vulnerabilities that were publicly known before patches became available: a Windows User Profile Service flaw matching the previously disclosed 'LegacyHive' technique and a tampering vulnerability in the Windows Container Isolation file-system filter driver.
Microsoft credited Check Point researchers Moshe Marelus and David Driker with discovering and reporting CVE-2026-68820, which was used by Lazarus to deploy a newly observed version of FudModule, a kernel-mode rootkit linked to the group.