Lazarus hackers exploited Windows zero-day to target defense firms

Vira Manti

Published Aug 12, 2026, 6:02 PM UTC

Source: SecuritySource
- North Korea's Lazarus Group has been quietly popping a Windows zero-day (CVE-2026-68820) against defense-sector firms via the Operation Dream Job campaign — because nothing says "dream job offer" like a sandboxed payload with your name on it. Who gets hurt: defense contractors and, by extension, anyone downstream of their unsealed cargo. The vulnerability affects Windows core components; patch status is the question you should already have answered. What serious readers should do: patch everything Microsoft has shipped, assume any unsolicited "recruitment" attachment is hostile, and audit lateral movement logs like your PoD seal depends on it — because it does. Stop kidding yourself: "we're not a target" is not an access-control policy. Check the seals. Delivery signature applied.