Yes — this is an actively exploited Windows kernel zero-day used by the North Korean Lazarus group in the "Operation Dream Job" campaign against defense, aerospace, and aviation organizations. CVE-2026-68820 (use-after-free in the AFD.sys/WinSock driver, CVSS 7.0) enables local privilege escalation to SYSTEM and leads to deployment of the FudModule rootkit. Microsoft released a fix on August 11, 2026, and CISA added the CVE to its KEV catalog. For any organization running Windows, this means one priority: apply the August update immediately and check for signs of pre-patch compromise.
Key facts
- CVE-2026-68820 is a use-after-free in the AFD.sys (Ancillary Function Driver for WinSock) kernel driver, rated CVSS 7.0 — a local attacker can escalate privileges to SYSTEM.
- Microsoft added the CVE to the CISA KEV catalog on August 11, 2026 as actively exploited and shipped a fix in the August Patch Tuesday (400 flaws, including 3 zero-days).
- Check Point Research confirms that Lazarus (DPRK) used CVE-2026-68820 as a zero-day in the "Operation Dream Job" campaign since early 2026, targeting defense, aerospace, and aviation.
- After successful privilege escalation, attackers deployed a new version of FudModule — a kernel-level rootkit enabling activity concealment and persistent access.
- The entry vector is fake job offers (recruiter lures) — social engineering rather than a direct network attack, which complicates early detection.
Decision table: what we know → what it means for B2B / manufacturing → what to do
| Area | What we know | What it means for B2B/manufacturing | Recommended action 30/90 days |
|---|---|---|---|
| Patch management | Fix available since Aug 11, 2026; CVE in KEV | Unpatched workstations and servers are exposed to SYSTEM escalation | Deploy August Patch Tuesday within 30 days; audit OT/IT environments for gaps |
| Affected surface | Windows with active WinSock (virtually all); typically engineering workstations, terminals, servers | One compromised local account can yield full machine control | Network segmentation, least-privilege, monitor escalation events (4688) |
| Supply chain / social engineering | Vector: fake job offers; targets: defense, aerospace, aviation | Risk for firms holding sensitive projects and partner data | Anti-phishing training, report-unauthorized-recruitment policy, verify contacts |
| Post-compromise detection | FudModule rootkit hides activity at kernel level | Classic EDR may miss it; requires memory and kernel-artifact analysis | Collect artifacts (memory dumps, 4688/1102 logs), incident response plan |
| NIS2 compliance | NIS2 art. 21 — risk-management measures covering vulnerabilities and supply chain | A KEV-listed, actively exploited flaw signals patch-process review | Document patching, report incidents; consult a law firm on interpretation |
Perspective of Marcin Białczyk (CHORS.NET)
From an operator's standpoint working with production environments daily, this incident has two layers. The first is purely technical: a use-after-free in AFD.sys is a classic kernel flaw, but Lazarus weaponizing it as a zero-day with the FudModule rootkit means we are dealing with a state-sponsored actor running a full operational cycle — from initial access to concealment and exfiltration. In production environments there is no room for "let's wait for stability" when patching — delay here is a real risk of SYSTEM-level escalation on machines touching lines and data.
The second layer is supply chain and social engineering. "Operation Dream Job" does not start with an exploit — it starts with an attractive job offer. Defense, aerospace, and aviation firms are targets both directly and indirectly: their subcontractors and suppliers are often gateways to sensitive projects. In my operational experience, the most neglected area is verifying recruiting contacts and controlling which machines have access to what. [[ADD HERE — specific deployment case with a manufacturing/defense client, if available]]
A third observation concerns detection. When a rootkit runs at kernel level, classic EDR signals are often insufficient. That is why in practice I recommend: (1) immediate patching, (2) reviewing privilege-escalation and kernel events from early 2026, (3) readiness for memory analysis on machines that may have touched the campaign. This is a passive, defensive approach — we inspect what we have, without guaranteeing detection of everything, while closing the most likely paths.
Frequently asked questions
Does CVE-2026-68820 only affect the defense sector?
No. The flaw sits in AFD.sys, present in virtually every Windows installation. The Lazarus campaign targets mainly defense, aerospace, and aviation, but any organization running Windows is technically exposed if unpatched.
Is the Microsoft August update sufficient?
Yes, for this specific flaw — Microsoft patched CVE-2026-68820 on August 11, 2026. However, if compromise occurred before the patch, patching alone does not remove the FudModule rootkit; verification is required.
How can I check whether my organization was attacked?
Review privilege-escalation events (e.g., Windows event 4688), kernel logs, unexpected new services, and memory artifacts since early 2026. In practice, also review recruiting contacts for fake offers.
Does this threat relate to NIS2?
Yes — NIS2 (art. 21) requires risk-management measures covering vulnerabilities and supply chain. An actively exploited, KEV-listed flaw is a practical trigger for reviewing patch processes and incident reporting. Legal interpretation requires consultation with a law firm.
How CHORS.NET helps
CHORS.NET supports the technical-operational side: passive exposure assessment, configuration verification, evidence packs and NIS2/KSC readiness support. See: Services, About CHORS.NET and Contact.
Boundaries and assumptions
- We are not a 24/7 SOC and do not guarantee detection of every incident or prevention of all attacks.
- We do not certify NIS2/KSC compliance and do not issue standalone legal opinions; we cooperate with law firms on legal interpretation.
- Results and recommendations reflect the state at the time of publication (August 2026) and may change.
- This material is informational and technical; it does not constitute legal advice.
Sources
- CISA — Known Exploited Vulnerabilities Catalog (KEV)
- Check Point Research — "Shattering the Dream: When a Job Offer Becomes a Zero-Day Attack"
- BleepingComputer — "Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days"
- SecurityWeek — "August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day"
- The Hacker News — "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day"
- Lansweeper — "Microsoft Patch Tuesday – August 2026"
Footer
Author: Marcin Białczyk, Eng., Founder & Cybersecurity Operator at CHORS.NET Last updated: 2026-08-12