Lazarus Group Exploits Zero-Day Flaw to Deliver Malware Through Fake Job Offers
Microsoft's August Patch Tuesday release addressed 398 vulnerabilities, including three zero-day flaws. Among them was CVE-2026-68820, a use-after-free bug in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows an attacker to run a specially crafted application and gain SYSTEM privileges.
Check Point Research identified North Korea's Lazarus group as the operator behind the exploit, which was used as part of Operation Dream Job. The attackers impersonated privacy technology firm Enveil and delivered malware through fake job offers via LinkedIn.
The flaw was rated CVSS 7.0 and considered Important by Microsoft. However, Tenable Senior Staff Research Engineer Satnam Narang noted that the tradecraft looked like an APT group working in limited, targeted attacks, with no exploit details made public yet at the time.
Microsoft's advisory for CVE-2026-68820 stated that a locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. No user interaction was required.