FILTERING BY: CLEAR FILTER

Lazarus Group Exploits Windows Zero-Day CVE-2026-68820 to Target Defense Industry

The Lazarus Group, a North Korean state-sponsored threat actor, is executing a sophisticated espionage campaign against high-value defense organizations and U.S. federal agencies. The attack chain leverages a Windows zero-day vulnerability, identified as CVE-2026-68820, delivered through modified PDF viewers embedded in malicious job application documents. This social engineering tactic facilitates initial access, leading to the deployment of specialized malware aimed at exfiltrating sensitive intellectual property, including post-quantum cryptography research. Due to the high criticality of this exploitation, CISA has issued a mandatory 14-day patching directive for all federal entities to mitigate the risk of infiltration and intellectual property theft.


LINK COPIED TO CLIPBOARD