Lazarus hackers exploited Windows zero-day to target defense firms
Summary
North Korean hackers, identified as Lazarus, have been exploiting a previously unknown Windows zero-day vulnerability (CVE-2026-68820) in an ongoing campaign dubbed Operation Dream Job. The attackers are specifically targeting defense sector companies with this exploit.
IFF Assessment
The exploitation of a zero-day vulnerability by a known threat actor targeting critical infrastructure represents a significant threat to defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: August 25, 2026. Known ransomware use: Unknown.
Defender Context
This highlights the persistent threat of nation-state actors and the critical need for robust endpoint detection and response (EDR) and timely patching, even for zero-day vulnerabilities. Defenders should remain vigilant for indicators of compromise associated with the Lazarus group and Operation Dream Job.