Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for Windows kernel zero-day CVE-2026-68820 exploited by North Korea Lazarus Group with CISA patch deadline 25 August 2026

Windows Kernel Zero-Day Used by North Korea — Patch Deadline Is Today

CISA has set today — 25 August — as the remediation deadline for CVE-2026-68820, a Windows kernel vulnerability that North Korea’s Lazarus Group exploited as a zero-day for at least five weeks before Microsoft patched it on 11 August. The flaw sits in afd.sys, the kernel driver behind every Windows network socket, and lets a local attacker escalate to SYSTEM privileges — full control of the machine — without any user interaction.

Lazarus used the flaw as part of Operation Dream Job, a long-running campaign that lures targets with fake recruitment offers, deploys a trojanised PDF viewer, and then drops a kernel-mode rootkit called FudModule to disable EDR and security monitoring. The confirmed targets so far have been defence and aerospace firms in Europe and India, but the underlying vulnerability exists on every Windows 10 and 11 endpoint. In our experience managing Australian SMB environments, Patch Tuesday reboots routinely slip — staff defer the restart, and a week later 20–30 per cent of endpoints still haven’t applied the fix. This particular patch replaces a kernel driver and won’t take effect until the machine actually reboots.

Check that every Windows endpoint in your environment has the August cumulative update installed — and has actually rebooted since 11 August. If you manage devices through Intune or an RMM tool, run a compliance report now. Any machine that shows the patch as “pending restart” is still vulnerable. Prioritise laptops and remote workers, who are the least likely to have rebooted.

If you’re not sure whether your fleet is patched, get in touch. Our managed IT clients have automated patch compliance and forced reboot policies — exactly the kind of thing that stops a five-week exploitation window before it starts.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →