Published Security3 min read
Lazarus puts a CVSS 7.0 driver bug at the front of the August patch queue
Check Point says Operation Dream Job now escalates to kernel through CVE-2026-68820, an AFD/WinSock use-after-free rated only Important in a release with 42 Critical fixes. CISA set an August 25 deadline.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Check Point reported Tuesday that the North Korean threat actor Lazarus Group renewed its Operation Dream Job campaign, now exploiting a Windows zero-day patched this week to spread its backdoors.
- One attack chain exploits a use-after-free privilege escalation vulnerability in the Windows Ancillary Function Driver (AFD) for WinSock, tracked as CVE-2026-68820.
- CVE-2026-68820 was reported by Check Point to Microsoft and patched as part of Microsoft's August 2026 Patch Tuesday updates.
- CISA added the flaw to its Known Exploited Vulnerabilities catalog, with federal civilian executive branch agencies ordered to patch by August 25.
- CVE-2026-68820 carries a CVSS score of 7.0 and is rated Important.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Check Point reported Tuesday that North Korea's Lazarus Group has renewed its Operation Dream Job campaign and is exploiting CVE-2026-68820, a use-after-free privilege escalation flaw in the Windows Ancillary Function Driver (AFD) for WinSock that Microsoft patched this week [1][2]. The bug was reported to Microsoft by Check Point and fixed in the August 2026 Patch Tuesday release, and CISA has added it to the Known Exploited Vulnerabilities catalog with a federal civilian patch deadline of August 25 [3][4].
The awkward part is the triage math. The flaw carries a CVSS score of 7.0 and is rated Important, which places it outside the 42 Critical patches shipped in the same August release [5][6][1]. That release fixed more than 400 security flaws in total, meaning at least 358 of them were not rated Critical [7][2]. Any organisation that sorts its patch queue by vendor severity will find the only bug in the batch with confirmed nation-state exploitation sitting in the second tier.
The targeting narrows who should care first. According to Check Point, the campaign opens with fraudulent job offers purportedly from well-known companies, delivered by direct message or through platforms such as LinkedIn, and aimed mainly at defense and aerospace organisations in Europe and India [8].
Check Point identified two attack chains [9]. In the first, the victim receives an archive containing a malicious DLL, an encrypted payload disguised as a PDF, and a legitimately signed PDF viewer called SmartaPDF.exe; launching the viewer sideloads libmupdf.dll, which decrypts the payload, shows a decoy document, and runs a downloader known as MISTPEN [10]. MISTPEN reaches attacker infrastructure through the Microsoft Graph API and OneDrive, runs reconnaissance and persistence modules, then uses CVE-2026-68820 to reach kernel level [11]. That access is what enables FudModule v3.1, a rootkit that disables logging, suppresses security software, and in this version also disrupts Smart App Control [12]. The chain ends in the ForestTiger backdoor [13].
The second chain skips the kernel entirely: victims are directed to a domain impersonating the privacy technology firm Enveil to download a trojanized viewer called SecurityPDF, which scans opened PDFs for a hidden marker and then loads a new backdoor named Troy directly in memory [14][15]. Troy supports 17 commands, including interactive shell access, process termination, in-memory DLL injection, and file enumeration, upload, download, and archived exfiltration [16].
Denis Calderone, CTO at Suzu Labs, told SC Media this is at least the third time in two years that Lazarus has exploited a bug in a driver Windows ships by default in order to deploy FudModule, after CVE-2024-21338 in appid.sys and CVE-2024-38193 in AFD.sys [17]. Two of those three were in AFD.sys [3]. "AFD.sys handles every socket operation on every Windows machine. You can't blocklist it," Calderone said, describing the shift away from bring-your-own-vulnerable-driver after defenders adopted driver allowlisting [18].
Infrastructure is also moving off attacker-owned hosts. Check Point says Lazarus increasingly serves ForestTiger from compromised WordPress and Roundcube Webmail servers, many of the latter vulnerable to CVE-2025-49113, with several instances carrying a PHP webshell dubbed RelayShell [19][20]. The researchers counted at least 17 unique server identifiers in that relay network and observed operators connecting through commercial VPN services [21].
Watch whether contractor and supplier endpoints in defense and aerospace get the same August 25 urgency as federal ones, since the campaign targets that sector rather than government networks [4][8]. Watch the Smart App Control interference specifically: it is the newest capability Check Point attributes to FudModule v3.1 [12]. And for anyone running Roundcube, CVE-2025-49113 is now an on-ramp to someone else's relay network [20].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Check Point reported Tuesday that the North Korean threat actor Lazarus Group renewed its Operation Dream Job campaign, now exploiting a Windows zero-day patched this week to spread its backdoors.
- [2]
One attack chain exploits a use-after-free privilege escalation vulnerability in the Windows Ancillary Function Driver (AFD) for WinSock, tracked as CVE-2026-68820.
ReportedView cited source - [3]
CVE-2026-68820 was reported by Check Point to Microsoft and patched as part of Microsoft's August 2026 Patch Tuesday updates.
ReportedView cited source - [4]
CISA added the flaw to its Known Exploited Vulnerabilities catalog, with federal civilian executive branch agencies ordered to patch by August 25.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- scworld.comLaura FrenchAug 14DPRK’s Lazarus Group exploits Windows zero-day in backdoor campaign
Additional citations
- Check Point, via SC World
- Check Point
- Denis Calderone, CTO at Suzu Labs, to SC Media
- Check Point Research blog post




