news.mlab.sh
Back to the feed
threat-intel

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

Critical
Image: The Record
Summary

The CISA has ordered federal agencies to patch a critical Windows vulnerability being actively exploited by North Korean hackers as part of Operation ‘Dream Job’. This campaign, led by the Lazarus Group, impersonates recruiters to target individuals applying for jobs in defense and aerospace, leveraging a zero-day exploit (CVE-2026-68820) to gain full control of compromised systems. The campaign has been ongoing since 2020 and has involved mimicking legitimate organizations like Lockheed Martin and Enveil to trick victims into opening malicious PDFs, ultimately granting long-term remote access.

Read the full article at The Record

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.