Federal agencies have been given a two-week deadline by the Cybersecurity and Infrastructure Security Agency (CISA) to patch a Microsoft vulnerability exploited by North Korean hackers in a long-running campaign. The bug was discovered after researchers analyzed the campaign's tactics, which involved targeting the job application process. This vulnerability poses a significant threat to federal agencies, and CISA's directive underscores the urgency of addressing the issue. The agency's move is aimed at preventing further exploitation of the bug, which could compromise sensitive information. The campaign's use of the vulnerability highlights the sophistication of North Korean hackers and their ability to adapt and evolve their tactics. This development serves as a reminder of the importance of timely patching and vulnerability management, so practitioners must prioritize patching to prevent similar exploits and protect their systems from nation-state threats1.