CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
Federal agencies were ordered to patch a Windows vulnerability used by North Korean hackers to target people applying to jobs in the defense and aerospace industry.
The Cybersecurity and Infrastructure Security Agency (CISA) and Microsoft confirmed on Tuesday that CVE-2026-68820 is being exploited. The bug was the only vulnerability in Microsoft’s Patch Tuesday release that the company confirmed is being used in real-world attacks.
The vulnerability impacts Winsock, a tool that acts as a bridge allowing web browsers to connect to the internet.
Nightwing's Nick Carroll compared the bug, which carries a seven out of ten severity score, to an intruder slipping through a closing door to print their own all-access VIP badge for a secure facility.
CISA gave federal agencies until August 25 to patch the bug. A device restart is required and there is no workaround to the issue. Automox CTO Jason Kikta noted that the same component was previously exploited in 2024 by the Lazarus Group, an infamous hacking operation run out of North Korea’s Reconnaissance General Bureau.
Kikta said the vulnerability requires two steps: an attacker would need to phish their way into a low-privileged foothold before using it.
“Treat this as the month's deadline item. It's the one confirmed-exploited bug in the release, and it applies to every Windows endpoint you manage. Put the noise to work. This exploitation pattern is detectable, but only if your detection actually covers kernel-driver race abuse,” Kikta added.
Operation ‘Dream Job’
Check Point said it disclosed the bug to Microsoft after discovering it as part of its examination into the latest wave of attacks that are part of Operation ‘Dream Job’ — a long-running campaign by North Korean hackers to exploit the job application process.
A Check Point report released on Tuesday said Lazarus Group hackers impersonated recruiters for Lockheed Martin and privacy-tech firm Enveil, contacting people on LinkedIn and other sites before sending candidates malicious PDF files. Once the files are opened, a backdoor is enabled that provides Lazarus hackers with long term remote access.
Check Point researchers explained that the malware first gathers information about the infected device before deploying an exploit for CVE-2026-68820.
They initially thought the issue was related to a past vulnerability fixed last year but further testing proved it was a new bug. The flaw “allows an attacker who has already gotten malware onto a machine to escalate from limited access to complete control of it, the kind of control normally reserved for the operating system itself.”
Sergey Shykevich, director of threat intelligence at Check Point, said what made the campaign dangerous is not just the zero-day vulnerability but Lazarus’ ability to weave legitimate, trusted infrastructure into every stage of the attack.
“They hid in plain sight, behind top-ranked search results, real vendor branding, and the reputation of organizations they had already compromised,” he said. “When the website, the download and the recruiter all appear authentic, the old advice to 'spot the phishing link' is no longer easily applicable.”
The researchers found targets spanning several defense sectors — including surveillance sensors, drones and robotics — in France, Germany, Brazil and India.
Threat researchers at several companies have been tracking the Operation DreamJob campaign since 2020. Google warned in 2022 that 250 people working for 10 different news media, domain registrars, web hosting providers and software vendors were targeted by the campaign, receiving malicious emails from fake recruiters claiming to be from Disney, Google and Oracle.
ESET previously tracked compromises related to the campaign in India, Poland, the U.K. and most recently Italy.
CISA’s decision to order federal agencies to patch the bug comes after FBI officials said they are currently investigating an incident where an unidentified federal agency mistakenly hired an IT worker from North Korea as part of the country’s long-running campaign to infiltrate organizations globally.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



