421 bugs in Microsoft’s Patch Tuesday release, and the Norks have already attacked one
Microsoft's August 2026 Patch Tuesday fixed 421 vulnerabilities, a slightly lighter load than the previous month's record but likely reflective of a new normal driven by AI-assisted vulnerability discovery and patching. The standout issue is CVE-2026-68820, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock that North Korea's Lazarus Group exploited as a zero-day from early June, allowing SYSTEM-level code execution without user interaction. The flaw's active exploitation before a patch existed makes it a priority for defenders, particularly given its link to an ongoing espionage campaign.
Check Point researchers, who discovered and reported the bug, linked its exploitation to Operation Dream Job, a long-running Lazarus campaign that lures job seekers with fake postings impersonating firms such as Lockheed Martin and Enveil, using SEO-boosted fake websites to distribute a trojanised PDF viewer called SecurityPDF. Opening malicious PDFs triggers a new backdoor named Troy, and attackers used the zero-day to deploy an updated version of Lazarus's FudModule kernel-mode rootkit. The campaign, targeting defence-sector organisations in Europe and India, aims to steal intellectual property, conduct espionage, and gather financial data, continuing Lazarus's long history of activity since at least 2009, including the 2014 Sony hack and 2017 WannaCry outbreak.
- Microsoft patched 421 bugs in August 2026's Patch Tuesday.
- North Korea's Lazarus Group exploited one flaw as a zero-day since June.
- Attack tied to "Dream Job" campaign targeting defence firms via fake job sites.