CybersecurityAugust 12, 2026· via BleepingComputer

North Korean hackers weaponize Windows zero-day against defense firms

North Korean hackers weaponize Windows zero-day against defense firms

Image : BleepingComputer

North Korean state-sponsored hackers have quietly turned a previously unknown Windows vulnerability into a precision-guided spear for infiltrating defense contractors. Microsoft’s Threat Intelligence Center reports that the Lazarus Group is actively exploiting CVE-2026-68820—a local privilege escalation flaw in the Windows Kernel—within Operation Dream Job, a long-running campaign aimed at stealing sensitive military and aerospace data.

A stealthy escalation path

The flaw allows attackers who already have a foothold on a victim’s machine to leap from a standard user account to full system privileges. By combining it with carefully crafted phishing lures disguised as job offers, Lazarus operators sidestep traditional defenses and burrow deep into high-value networks. Microsoft credits Google’s Threat Analysis Group for first spotting the exploit chain in mid-May and promptly rolling out mitigations.

Supply-chain echoes

Once inside, the intruders deploy custom backdoors and credential-stealing tools to map internal systems and harvest credentials. Security researchers note that the same campaign has previously masqueraded as recruitment emails sent to engineers at aerospace and defense firms across Europe and North America. The attackers’ reuse of the zero-day across multiple victims underscores the value placed on maintaining long-term access to strategic targets.

Why it matters

This incident illustrates how rapidly zero-days are commoditized by advanced persistent threat groups. For defense contractors, it reinforces the need to layer endpoint detection with rigorous identity verification and prompt patching of high-risk systems. For the broader tech ecosystem, it highlights the growing pressure on vendors to shorten the window between exploit discovery and public disclosure. The Lazarus campaign may be targeted, but the tactics and techniques are likely to propagate, making proactive threat hunting a business necessity rather than a luxury.


Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on BleepingComputer →

← Back to home