Loading article…
Microsoft patched CVE‑2026‑68820 on Aug 11 after Check Point found Lazarus using it to deploy the FudModule rootkit. Enterprises must update Windows 11 builds
Microsoft released an August 11 update that closes CVE‑2026‑68820, a kernel‑level zero‑day in the AFD.sys driver that North Korea’s Lazarus group has been exploiting to install its FudModule v3.1 rootkit [2]. The fix arrives after the vulnerability was shown to give attackers SYSTEM privileges, underscoring the urgency for organizations—especially those in defense, aerospace and aviation—to apply the patch immediately.
| At a glance | |
|---|---|
| Vulnerability | CVE‑2026‑68820 (AFD.sys kernel driver) |
| Patch date | August 11, 2026 (August Patch Tuesday) |
| Exploited by | Lazarus group (North Korean threat actor) |
| Rootkit deployed | FudModule v3.1 (kernel‑mode) |
Check Point Research traced the exploit to two parallel infection chains that begin with malicious PDF viewers delivered via social‑engineering job offers. After a victim opens the PDF, a sideloaded DLL decrypts a payload that runs MISTPEN, a downloader that uses the Microsoft Graph API to fetch additional modules from attacker‑controlled OneDrive storage. The final stage triggers the AFD.sys flaw, granting SYSTEM‑level access and loading FudModule v3.1 [2]. The rootkit disables telemetry callbacks, kills the NT Kernel Logger, and blinds more than 90 ETW providers, while also tampering with Microsoft Defender’s Smart App Control. In earlier versions, a dedicated Defender‑disabling routine existed; the new variant uses a generic suppression engine instead [2].
The August patch follows a record‑breaking July Patch Tuesday that addressed 570 vulnerabilities—almost three times the previous month’s total [1]. The scale of the update highlights Microsoft’s growing backlog of critical bugs, but the active exploitation of CVE‑2026‑68820 shows that zero‑days can remain in the wild for months, as seen in other Lazarus campaigns that have persisted for up to six months before disclosure [3]. Enterprises should not only apply the patch but also audit outbound traffic to Roundcube, WordPress or PrestaShop sites that may be serving as covert relay nodes for the group’s command‑and‑control traffic [2].
The August fix closes a critical attack path that let Lazarus move from user‑level compromise to full kernel control, but the group’s use of sophisticated delivery chains and hijacked web infrastructure suggests that detection will remain a challenge until broader network‑level defenses are hardened.
Coverage is mostly measured — 206 of 206 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 3 outlets · Aug 13, 2026 · How we report
Microsoft was founded on April 4, 1975, by Bill Gates and Paul Allen.
The U.S. Department of Justice and 20 states accused Microsoft of illegally maintaining an operating system monopoly by bundling Internet Explorer with Windows.
Microsoft leadership directed engineers to quickly test and deploy the DeepSeek R1 model on Azure AI Foundry and GitHub.