
Microsoft addressed 421 security flaws in its August Patch Tuesday release, including a critical zero-day vulnerability already exploited by North Korea's Lazarus Group.
The zero-day, tracked as CVE-2026-68820, is a use-after-free bug in the Windows Ancillary Function Driver that allows attackers to execute code with SYSTEM-level privileges.
Researchers at Check Point observed the Lazarus Group using this flaw in 'Operation Dream Job' to deploy a backdoor named Troy against defense sector targets in India and Europe.