Lazarus Group Exploits Zero-Day Vulnerability in Microsoft Windows
Microsoft's August Patch Tuesday release addressed 421 bugs in its own products, about 200 fewer CVEs than last month. However, this is likely to be the new norm due to AI-assisted vulnerability disclosures and fixes.
The big news is that North Korea's Lazarus Group (and possibly other miscreants) found and attacked one of these flaws as a zero-day in early June. The bug, tracked as CVE-2026-68820, is a use-after-free in the Windows Ancillary Function Driver for WinSock.
An attacker could run a specially crafted application on an affected system to trigger a race condition, allowing them to execute code with SYSTEM-level privileges and no user interaction required. Microsoft credited Check Point researchers Moshe Marelus and David Driker with finding and reporting CVE-2026-68820.
The security shop's threat intel lead, Sergey Shykevich, stated that his analysts first observed attackers - namely North Korea's Lazarus Group - battering this CVE at the beginning of June. They assume it was used widely in the campaign.