CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

Federal agencies were ordered to patch a Windows vulnerability used by North Korean hackers to target people applying to jobs in the defense and aerospace industry.
The Cybersecurity and Infrastructure Security Agency (CISA) and Microsoft confirmed on Tuesday that CVE-2026-68820 is being exploited. The bug was the only vulnerability in Microsoft’s Patch Tuesday release that the company confirmed is being used in real-world attacks.
The vulnerability impacts Winsock, a tool that acts as a bridge allowing web browsers to connect to the internet.
Nightwing's Nick Carroll compared the bug, which carries a seven out of ten severity score, to an intruder slipping through a closing door to print their own all-access VIP badge for a secure facility.
CISA gave federal agencies until August 25 to patch the bug. A device restart is required and there is no workaround to the issue. Automox CTO Jason Kikta noted that the same component was previously exploited in 2024 by the Lazarus Group, an infamous hacking operation run out of North Korea’s Reconnaissance General Bureau.
Kikta said the vulnerability requires two steps: an attacker would need to phish their way into a low-privileged foothold before using it.
“Treat this as the month's deadline item. It's the one confirmed-exploited bug in the release, and it applies to every Windows endpoint you manage. Put the noise to work. This exploitation pattern is detectable, but only if your detection actually covers kernel-driver race abuse,” Kikta added.
Operation ‘Dream Job’
Check Point said it disclosed the bug to Microsoft after discovering it as part of its examination into the latest wave of attacks that are part of Operation ‘Dream Job’ — a long-running campaign by North Korean hackers to exploit the job application process.
A Check Point report released on Tuesday said Lazarus Group hackers impersonated recruiters for Lockheed Martin and privacy-tech firm Enveil, contacting people on LinkedIn and other sites before sending candidates malicious PDF files. Once the files are opened, a backdoor is enabled that provides Lazarus hackers with long term remote access.
Check Point researchers explained that the malware first gathers information about the infected device before deploying an exploit for CVE-2026-68820.
They initially thought the issue was related to a past vulnerability fixed last year but further testing proved it was a new bug. The flaw “allows an attacker who has already gotten malware onto a machine to escalate from limited access to complete control of it, the kind of control normally reserved for the operating system itself.”
Sergey Shykevich, director of threat intelligence at Check Point, said what made the campaign dangerous is not just the zero-day vulnerability but Lazarus’ ability to weave legitimate, trusted infrastructure into every stage of the attack.
“They hid in plain sight, behind top-ranked search results, real vendor branding, and the reputation of organizations they had already compromised,” he said. “When the website, the download and the recruiter all appear authentic, the old advice to 'spot the phishing link' is no longer easily applicable.”
The researchers found targets spanning several defense sectors — including surveillance sensors, drones and robotics — in France, Germany, Brazil and India.
Threat researchers at several companies have been tracking the Operation DreamJob campaign since 2020. Google warned in 2022 that 250 people working for 10 different news media, domain registrars, web hosting providers and software vendors were targeted by the campaign, receiving malicious emails from fake recruiters claiming to be from Disney, Google and Oracle.
ESET previously tracked compromises related to the campaign in India, Poland, the U.K. and most recently Italy.
CISA’s decision to order federal agencies to patch the bug comes after FBI officials said they are currently investigating an incident where an unidentified federal agency mistakenly hired an IT worker from North Korea as part of the country’s long-running campaign to infiltrate organizations globally.
References in this story
- CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA www.cisa.gov
- Microsoft Security Response Center (@msftsecresponse) on X x.com Security updates for August 2026 are now available. Details are here: https://t.co/WW89TchdN8
- Chemical sector targeted by North Korea-linked hacking group, researchers say therecord.media An espionage campaign from North Korea’s Lazarus Group has now turned its attention to chemical sector organizations in South Korea, according to a report from cybersecurity company Symantec.
- State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit… blog.checkpoint.com It typically begins the same way it has for years, with an approach from a recruiter offering a role at a company the target would recognize, accompanied %Check Point Research uncovers a Lazarus campaign targeting…
- North Korean hackers target employees of news outlets, software vendors and more through Chrome vulnerability therecord.media Google has released a report identifying two North Korean government hacking campaigns that exploited a Google Chrome 0-day.
- North Korean hacking group targeting European drone maker with ScoringMathTea malware therecord.media Researchers at ESET said they found evidence of a new tentacle of the long-running Operation DreamJob campaign — where North Korea’s Lazarus group sends malware-laden emails purporting to be from recruiters at top…
- FBI investigating North Korean remote IT staffer working for US agency | Federal News Network federalnewsnetwork.com Experts say the incident highlights potential gaps in government and industry vetting processes, especially for jobs like IT support work.
- North Korea IT worker scheme expanding to more industries, countries outside of US tech sector therecord.media Okta said their new research into the scheme revealed that North Korea has honed its skills on U.S.-based companies and has expanded into dozens of different countries and industries.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
- jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51


