Vulnerabilities

CVE-2026-68820: Microsoft Bug Exploited in DPRK Campaign

August 13, 2026 04:10 · 10 min read
CVE-2026-68820: Microsoft Bug Exploited in DPRK Campaign

The Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies two weeks to patch a Microsoft bug exploited in a campaign by North Korean hackers. The bug, identified as CVE-2026-68820, is a Windows vulnerability that impacts Winsock, a tool that acts as a bridge allowing web browsers to connect to the internet.

Vulnerability Details

CVE-2026-68820 carries a severity score of seven out of ten and requires two steps to exploit: an attacker would need to phish their way into a low-privileged foothold before using it. The vulnerability allows an attacker who has already gotten malware onto a machine to escalate from limited access to complete control of it.

Exploitation Pattern

Automox CTO Jason Kikta noted that the same component was previously exploited in 2024 by the Lazarus Group, an infamous hacking operation run out of North Korea’s Reconnaissance General Bureau. Kikta said that the exploitation pattern is detectable, but only if detection actually covers kernel-driver race abuse.

Check Point researchers discovered the bug as part of its examination into the latest wave of attacks that are part of Operation ‘Dream Job’ — a long-running campaign by North Korean hackers to exploit the job application process. The researchers found that the malware first gathers information about the infected device before deploying an exploit for CVE-2026-68820.

Operation 'Dream Job'

Operation 'Dream Job' is a campaign where North Korean hackers impersonate recruiters for major companies, contacting people on LinkedIn and other sites before sending candidates malicious PDF files. Once the files are opened, a backdoor is enabled that provides Lazarus hackers with long-term remote access.

Threat researchers at several companies have been tracking the Operation DreamJob campaign since 2020. Google warned in 2022 that 250 people working for 10 different news media, domain registrars, web hosting providers, and software vendors were targeted by the campaign, receiving malicious emails from fake recruiters claiming to be from Disney, Google, and Oracle.

CISA's Response

CISA has ordered federal agencies to patch the bug by August 25. A device restart is required, and there is no workaround to the issue. CISA's decision comes after FBI officials said they are currently investigating an incident where an unidentified federal agency mistakenly hired an IT worker from North Korea as part of the country’s long-running campaign to infiltrate organizations globally.

CISA and Microsoft confirmed on Tuesday that CVE-2026-68820 is being exploited. The bug was the only vulnerability in Microsoft’s Patch Tuesday release that the company confirmed is being used in real-world attacks.

“Treat this as the month's deadline item. It's the one confirmed-exploited bug in the release, and it applies to every Windows endpoint you manage. Put the noise to work. This exploitation pattern is detectable, but only if your detection actually covers kernel-driver race abuse,” said Jason Kikta, Automox CTO.

Sergey Shykevich, director of threat intelligence at Check Point, said what made the campaign dangerous is not just the zero-day vulnerability but Lazarus’ ability to weave legitimate, trusted infrastructure into every stage of the attack. “They hid in plain sight, behind top-ranked search results, real vendor branding, and the reputation of organizations they had already compromised,” he said.

Conclusion

CVE-2026-68820 is a serious vulnerability that requires immediate attention from federal agencies. The bug has been exploited in the 'Dream Job' campaign, and CISA has ordered agencies to patch it by August 25. It is essential for organizations to prioritize patching this vulnerability to prevent potential attacks.

Organizations should take immediate action to patch CVE-2026-68820 and prevent potential attacks. It is crucial to prioritize patching this vulnerability to ensure the security of Windows endpoints.

Read more about the vulnerability and the 'Dream Job' campaign.

Source: The Record

Source: The Record

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free