The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that all federal agencies address a critical Windows vulnerability by August 25. This vulnerability, identified as CVE-2026-68820, has been actively exploited by North Korean hackers in a campaign aimed at individuals within the defense and aerospace sectors. Microsoft confirmed that this is the only vulnerability from their latest Patch Tuesday release being used in real-world attacks. The bug affects Winsock, a crucial component that facilitates internet connectivity for web browsers.

Experts have highlighted the severity of this bug with a score of seven out of ten. Nick Carroll from Nightwing likened it to an intruder gaining unauthorized access to a secure facility. To mitigate this threat, a device restart is essential, and no temporary workarounds are available. Jason Kikta, CTO of Automox, emphasized the importance of addressing this vulnerability, as it requires attackers to first gain a low-privileged foothold through phishing before exploiting it.

The vulnerability was disclosed to Microsoft by Check Point after it was discovered in connection with Operation Dream Job, a sophisticated campaign by the Lazarus Group. These hackers impersonated recruiters from high-profile companies like Lockheed Martin to deliver malicious PDF files to unsuspecting job seekers. Upon opening these files, a backdoor is installed, granting attackers prolonged remote access.

Check Point researchers noted that this new bug allows attackers to escalate privileges from limited access to full control over the system. Sergey Shykevich from Check Point highlighted the covert nature of the campaign, as hackers leveraged legitimate infrastructure to mask their activities. Targets have included various defense sectors in countries like France, Germany, Brazil, and India.

The urgency to patch this flaw follows an FBI investigation into an incident where a U.S. federal agency unknowingly hired an IT worker from North Korea, underscoring the persistent global threat of cyber infiltration by North Korean actors.