CISA Orders 14-Day Patch for Lazarus-Exploited Winsock Bug
Second Lazarus Group exploitation of the same Windows Winsock component in two years, this time delivered through spoofed Lockheed Martin recruiter personas: the kernel-driver layer is now a sustained DPRK targeting priority.
TL;DR
CISA added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog Tuesday, giving federal agencies until August 25 to patch a Windows Winsock use-after-free flaw that Lazarus Group is actively exploiting. The bug enables local privilege escalation to full OS control after an attacker gains initial foothold. It's the second time in two years Lazarus has targeted the same Winsock component, and Operation Dream Job's current wave uses compromised vendor infrastructure and spoofed Lockheed Martin recruiter accounts to deliver the payload, making "spot the phishing link" advice essentially useless.

For the second time in two years, North Korea's Lazarus Group has exploited a vulnerability in the Windows Winsock kernel driver to escalate from limited foothold to full OS control. CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities catalog on August 11 and set a mandatory remediation deadline of August 25 for all federal civilian executive branch agencies. A reboot is required and there's no workaround.
The recurrence matters. Automox CTO Jason Kikta noted Lazarus previously exploited the same Winsock component in 2024. The target set hasn't changed (defense primes, aerospace contractors, nuclear and engineering firms) but the delivery chain has. Check Point, which discovered the bug and disclosed it to Microsoft, documented a shift that should concern every CISO whose organization recruits engineers: Lazarus isn't just spoofing emails anymore.
Dream Job's infrastructural turn
The current wave of Operation Dream Job uses compromised third-party vendor websites, legitimate branding lifted from Lockheed Martin and privacy-tech firm Enveil, and LinkedIn recruiter personas to deliver malicious PDFs that deploy a backdoor. Once the backdoor establishes persistence, the malware fingerprints the device and then triggers the CVE-2026-68820 exploit to escalate privileges. The entire chain runs on infrastructure that passes casual inspection, top-ranked search results, real logos, the reputations of already-compromised organizations.
"Spot the phishing link" doesn't work when the link, the site, and the recruiter all look authentic. Check Point's Sergey Shykevich put it plainly: Lazarus hid in plain sight behind trust signals that security awareness training treats as green flags.
The campaign has hit defense-sector targets (surveillance sensors, drones, robotics) across France, Germany, Brazil, and India. Operation Dream Job has been running since at least 2020. Google warned in 2022 that 250 people across ten industries had been targeted with fake recruiter emails purporting to come from Disney, Google, Oracle, and other recognizable brands.
What's missing
CISA's KEV entry carries a two-week deadline for FCEB agencies, but the directive doesn't extend to defense contractors who handle CUI or covered defense information and who are being targeted by the same campaign. It's unclear whether CISA will issue sector-specific detection guidance for kernel-driver race abuse patterns (the exploitation technique at the heart of this bug) or whether the Department of Defense will separately mandate the patch for the defense industrial base. For now, the compliance obligation falls on the agencies, while the attackers are aiming at the supply chain.
Kikta's operational advice is direct: treat this as the month's deadline item. The exploitation pattern is detectable, but only if detection tooling covers kernel-driver race conditions. Many environments don't.
Published ·Deep Fathom