A recently discovered Windows zero-day vulnerability, now patched as CVE-2026-68820, has been exploited by the North Korean Lazarus Group in their Operation Dream Job campaign1. This campaign targets defense professionals with fake job offers, including those purporting to be from Lockheed Martin, to deploy backdoors and evade security controls. The latest iteration of Operation Dream Job is particularly concerning due to the use of this previously unknown vulnerability, which allows the group to gain unauthorized access to targeted systems. The campaign also utilizes a newly documented backdoor called Troy and leverages legitimate infrastructure to carry out its operations. The active exploitation of CVE-2026-68820 by North Korean actors underscores the need for prompt patching to prevent further compromise. So what matters to practitioners is that the exploitation status of this vulnerability demands immediate attention, making it a patch-now situation to prevent potential breaches.