Cybersecurity News • 2d
Microsoft Windows afd.sys Zero-Day Exploitation by Lazarus Group
The Lazarus Group exploited CVE-2026-68820, a critical zero-day vulnerability in the afd.sys (Ancillary Function Driver for Winsock) kernel driver of Microsoft Windows. The attack chain leverages social engineering via fraudulent job offers to establish initial user-level access, followed by a Local Privilege Escalation (LPE) exploit to achieve SYSTEM-level privileges. This elevation facilitates the deployment of the FudModule (v3) kernel-level rootkit for deep persistence and EDR evasion. Microsoft addressed the vulnerability in the August 2026 Patch Tuesday update.
Links:Cybersecurity News, gbhackers.com, blackhatnews.tokyo, cybersecurity.pk, SecurityWeek, En, feeds.feedburner.com, Blackswan-cybersecurity, Rewterz, Gendigital, Petri, Darkreading, Asec, Ibm, Securityaffairs, Medium, Windows, Helpnetsecurity, Cyberinsider, Cisa, Therecord, Thehackernews, Daily •