Lazarus hackers exploited Windows zero-day to target defense firms

Summary

North Korean hackers, identified as Lazarus, have been exploiting a previously unknown Windows zero-day vulnerability (CVE-2026-68820) in an ongoing campaign dubbed Operation Dream Job. The attackers are specifically targeting defense sector companies with this exploit.

IFF Assessment

FOE

The exploitation of a zero-day vulnerability by a known threat actor targeting critical infrastructure represents a significant threat to defenders.

Severity

7.0 High

CISA KEV: Listed as actively exploited. Federal patch due: August 25, 2026. Known ransomware use: Unknown.

Defender Context

This highlights the persistent threat of nation-state actors and the critical need for robust endpoint detection and response (EDR) and timely patching, even for zero-day vulnerabilities. Defenders should remain vigilant for indicators of compromise associated with the Lazarus group and Operation Dream Job.

Read Full Story →