BlackTree Security · Infrastructure · Automation · AI

North Korea

North Korea

CVE-2026-68820 Turns a Windows Foothold Into SYSTEM

Red exploit path crossing a Windows network-driver layer into a privileged kernel core

Microsoft’s August 2026 updates fix a WinSock privilege-escalation flaw used by North Korea’s Lazarus group against defence, aerospace and aviation organisations. The exploit helped Operation Dream Job turn a local Windows foothold into SYSTEM access, deploy a kernel rootkit and interfere with endpoint-security controls.