Windows Kernel Zero-Day Used by North Korea — Patch Deadline Is Today
CISA has set today — 25 August — as the remediation deadline for CVE-2026-68820, a Windows kernel vulnerability that North Korea’s Lazarus Group exploited as a zero-day for at least five weeks before Microsoft patched it on 11 August. The flaw sits in afd.sys, the kernel driver behind every Windows network socket, and lets a local attacker escalate to SYSTEM privileges — full control of the machine — without any user interaction.
Lazarus used the flaw as part of Operation Dream Job, a long-running campaign that lures targets with fake recruitment offers, deploys a trojanised PDF viewer, and then drops a kernel-mode rootkit called FudModule to disable EDR and security monitoring. The confirmed targets so far have been defence and aerospace firms in Europe and India, but the underlying vulnerability exists on every Windows 10 and 11 endpoint. In our experience managing Australian SMB environments, Patch Tuesday reboots routinely slip — staff defer the restart, and a week later 20–30 per cent of endpoints still haven’t applied the fix. This particular patch replaces a kernel driver and won’t take effect until the machine actually reboots.
Check that every Windows endpoint in your environment has the August cumulative update installed — and has actually rebooted since 11 August. If you manage devices through Intune or an RMM tool, run a compliance report now. Any machine that shows the patch as “pending restart” is still vulnerable. Prioritise laptops and remote workers, who are the least likely to have rebooted.
If you’re not sure whether your fleet is patched, get in touch. Our managed IT clients have automated patch compliance and forced reboot policies — exactly the kind of thing that stops a five-week exploitation window before it starts.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
