Microsoft released August 2026 security updates fixing 400 vulnerabilities across Windows and other products, including one zero-day already used in attacks. The exploited flaw, CVE-2026-68820, is a use-after-free bug in the Windows Ancillary Function Driver for WinSock that can let a local authenticated attacker gain SYSTEM privileges; Check Point says Lazarus used it to deploy a new FudModule rootkit. Microsoft also fixed two publicly disclosed zero-days, including CVE-2026-62832 in the Windows User Profile Service.
Bill Toulas
2026.08.12
93% relevant
This article adds attribution and exploitation context for CVE-2026-68820, saying Lazarus used the Windows AFD.sys privilege-escalation zero-day in Operation Dream Job against defense, aerospace, and aviation targets, including use of the FudModule rootkit and the Troy backdoor.
2026.08.12
95% relevant
This article covers the same August 2026 Microsoft Patch Tuesday event and adds detail that the release contains 419 vulnerabilities, 62 critical and 357 important issues, plus context on two publicly disclosed zero-days and the link between exploited CVE-2026-68820 and a Lazarus job-lure campaign targeting defense, aerospace, and aviation applicants.
2026.08.12
95% relevant
This adds that CISA has now added CVE-2026-68820 to the federal remediation list with an August 25 deadline, and ties the in-the-wild exploitation to Lazarus Group's Dream Job campaign using fake recruiter lures and malicious PDFs against defense and aerospace targets.
Ionut Arghire
2026.08.12
97% relevant
This article adds the attack attribution and intrusion details behind CVE-2026-68820, saying Lazarus exploited the Windows afd.sys zero-day in Operation Dream Job to gain SYSTEM privileges and deploy Mistpen, ForestTiger, Troy, and RelayShell against defense, aerospace, and aviation targets.
2026.08.11
93% relevant
This adds that the August Patch Tuesday total was 421 Microsoft bugs, and more importantly that Check Point observed Lazarus exploiting CVE-2026-68820 from early June in Operation Dream Job, using fake Lockheed Martin and Enveil job lures, trojanized SecurityPDF, the Troy backdoor, and a new FudModule rootkit variant.
BrianKrebs
2026.08.11
98% relevant
This is the same underlying August 2026 Patch Tuesday event and adds reporting detail on the scope of fixes (398 total, 42 critical), the exploited zero-day CVE-2026-68820 in afd.sys, and the two publicly disclosed issues CVE-2026-62832 and CVE-2026-72971.
info@thehackernews.com (The Hacker News)
2026.08.11
96% relevant
This article appears to cover the same August 2026 Microsoft Patch Tuesday event, reporting roughly the same flaw count and highlighting an actively exploited Windows driver zero-day as part of the release.
Ionut Arghire
2026.08.11
97% relevant
This article covers the same August 2026 Patch Tuesday event and adds specifics on the scale of the release (421 CVEs), the exploited zero-day CVE-2026-68820 in afd.sys, and other notable publicly disclosed and high-priority flaws including CVE-2026-62832, CVE-2026-72971, Windows DNS Server, Exchange Server, and Microsoft QUIC issues.
Lawrence Abrams
2026.08.11
100% relevant
This article establishes the broader August 2026 Microsoft Patch Tuesday event and introduces a separate tracked development: the actively exploited Windows zero-day CVE-2026-68820 tied by Check Point to Lazarus and FudModule deployment.