A recently discovered Windows zero-day vulnerability, now patched as CVE-2026-68820, has been exploited by the North Korean Lazarus Group in their Operation Dream Job campaign1. This campaign targets defense professionals with fake job offers, including those purporting to be from Lockheed Martin, to deploy backdoors and evade security controls. The latest iteration of Operation Dream Job is particularly concerning due to the use of this previously unknown vulnerability, which allows the group to gain unauthorized access to targeted systems. The campaign also utilizes a newly documented backdoor called Troy and leverages legitimate infrastructure to carry out its operations. The active exploitation of CVE-2026-68820 by North Korean actors underscores the need for prompt patching to prevent further compromise. So what matters to practitioners is that the exploitation status of this vulnerability demands immediate attention, making it a patch-now situation to prevent potential breaches.
North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job
⚠️ Critical Alert
Why This Matters
CVE-2026-68820 is in active discussion involving North Korea — exploitation status determines whether this is patch-now or monitor.
References
- SecurityAffairs. (2026, August 13). North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job. SecurityAffairs. https://securityaffairs.com/197098/uncategorized/north-korean-lazarus-group-uses-windows-zero-day-in-operation-dream-job.html
Original Source
SecurityAffairs
Read original →