Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

0
Critical
Vulnerabilitywindowszero-day
Published: 08/12/2026 (08/12/2026, 08:45:53 UTC)
Source: SecurityWeek

Description

A zero-day vulnerability in Windows' Ancillary Function Driver for WinSock (afd.sys), tracked as CVE-2026-68820, has been exploited by North Korean Lazarus Group hackers to gain full system control and deploy the ForestTiger backdoor. The attacks target defense, aerospace, and aviation sectors in multiple countries, including Europe and India, using fake job recruitment lures. The vulnerability is a use-after-free issue allowing privilege escalation to System. Microsoft released a patch on August 11, 2026, and CISA has added it to its Known Exploited Vulnerabilities catalog, urging prompt patching. The campaign also uses a trojanized PDF viewer to deploy the Troy backdoor and compromised webmail and CMS servers as command-and-control infrastructure.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/12/2026, 08:56:22 UTC

Technical Analysis

The vulnerability CVE-2026-68820 is a use-after-free flaw in Windows afd.sys that enables attackers to trigger a race condition and escalate privileges to System level. North Korean Lazarus Group has exploited this zero-day in a campaign targeting aerospace and defense organizations, primarily in Europe and India, since early 2026. Attackers use social engineering via fake job offers to deliver malicious payloads involving DLL sideloading and malware downloaders. The exploitation chain culminates in deploying the ForestTiger backdoor. Additionally, a trojanized PDF viewer named SecurityPDF is used to deploy the Troy backdoor in memory. The attackers' infrastructure includes compromised Roundcube webmail and CMS platforms vulnerable to CVE-2025-49113, hosting a PHP webshell called RelayShell for command relay. Microsoft patched the vulnerability on August 11, 2026, and CISA has mandated patching within two weeks for federal agencies.

Potential Impact

Successful exploitation allows attackers to gain full System privileges on affected Windows systems, enabling complete control over the victim machine. This facilitates deployment of persistent backdoors such as ForestTiger and Troy, enabling extensive espionage capabilities including file operations, shell access, process manipulation, and data exfiltration. The campaign targets sensitive sectors like defense and aerospace, potentially compromising critical intellectual property and operational security. The use of sophisticated infection chains and web-based command infrastructure increases stealth and persistence.

Mitigation Recommendations

Microsoft released an official patch for CVE-2026-68820 on August 11, 2026, as part of Patch Tuesday updates. Organizations, especially in defense, aerospace, and aviation sectors, should prioritize applying this update immediately. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog and urges federal agencies to patch within two weeks. Security teams should also scrutinize unsolicited recruitment communications and avoid downloading unverified payloads. Reviewing indicators of compromise related to ForestTiger, Troy backdoors, and associated infrastructure is recommended. No vendor advisory indicates that no action is required; patching is the primary mitigation.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.7,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks/","fetched":true,"fetchedAt":"2026-08-12T08:56:13.355Z","wordCount":1190}

Threat ID: 6a7c352dbf8831d5394902b2

Added to database: 08/12/2026, 08:56:13 UTC

Last enriched: 08/12/2026, 08:56:22 UTC

Last updated: 08/12/2026, 09:02:06 UTC

Views: 14

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses