Microsoft Windows Kernel Exploitation via Lazarus Group WinSock Zero-Day
The Lazarus Group conducted a five-week targeted campaign exploiting CVE-2026-68820, a WinSock zero-day vulnerability facilitating remote code execution (RCE) within the Windows kernel. Leveraging sophisticated social engineering via job-application-themed malicious PDF payloads, the threat actor targeted high-value defense and aerospace organizations. The campaign concurrently utilized a critical DNS Server RCE vulnerability (CVSS 9.8) with wormable potential, significantly increasing the risk of rapid lateral movement across enterprise networks. Remediation was achieved through Microsoft's August 2026 Patch Tuesday; however, the period of exposure necessitated an emergency CISA directive mandating federal agencies to implement patches within a strict 14-day window to mitigate ongoing state-sponsored risks.