Lazarus Rootkit Exploits Zero-Day Windows Vulnerability
A zero-day vulnerability in Windows has been exploited by attackers to deploy malware used by the North Korean hacking group Lazarus.
The vulnerability, CVE-2026-68820, is a high-rated issue that allows an authorized attacker to elevate privileges locally and gain system privileges. It was disclosed by Check Point Research after observing it being used to deploy a new version of FudModule, a kernel-mode rootkit.
Microsoft has released a patch for the vulnerability, which is already being tracked as exploited in the wild. The Cybersecurity and Infrastructure Security Agency added CVE-2026-68820 to its Known Exploited Vulnerabilities database on August 11.
Users are advised to prioritize patching this issue, with Microsoft Windows 10, Windows 11, Windows Server 2012, 2016, 2019, 2022 and 2025 impacted. Mike Walters of Action1 warns that a locally authenticated attacker could 'run a specially crafted application and trigger a race condition,' leading to privilege escalation.
The August 2026 Patch Tuesday update has covered no less than 421 vulnerabilities in all, including three zero-days, with CVE-2026-68820 being the only one listed as already confirmed exploited. Todd Schell of Ivanti notes that not all Common Vulnerabilities and Exposures are created equal, and the patches need to be triaged to identify those requiring immediate attention.