CISA Orders Fed Agencies to Patch Microsoft Winsock Bug Exploited by Lazarus
CISA has directed U.S. federal agencies to patch CVE-2026-68820, a Windows Winsock vulnerability actively exploited by North Korea's Lazarus Group, by August 25. The flaw, which carries a CVSS severity score of 7.0, affects every Windows endpoint and requires a device restart with no available workaround. Microsoft confirmed the bug as the only actively exploited vulnerability in this month's Patch Tuesday release, while Nightwing's Nick Carroll compared it to "an intruder slipping through a closing door to print their own all-access VIP badge for a secure facility."
The exploitation is part of Operation 'Dream Job,' a long-running Lazarus campaign that impersonates recruiters from defense and aerospace companies—most recently Lockheed Martin and privacy-tech firm Enveil—to contact targets on LinkedIn and other professional platforms. Candidates are sent malicious PDF files disguised as job descriptions; once opened, the documents deploy a backdoor granting the attackers persistent remote access. Check Point researchers, who discovered the vulnerability while investigating this latest wave, said the malware first gathers device information before exploiting CVE-2026-68820 to escalate privileges from limited user access to full system control—a level "normally reserved for the operating system itself."
"This isn't just a zero-day problem—it's Lazarus' ability to weave legitimate, trusted infrastructure into every stage of the attack that makes it dangerous," said Sergey Shykevich, director of threat intelligence at Check Point. Automox CTO Jason Kikta added that the same Winsock component was previously exploited by Lazarus in 2024 and warned that organizations should treat CVE-2026-68820 as the month's top priority, since it "applies to every Windows endpoint you manage."
For security teams, the campaign underscores the need for layered defenses. IT administrators can run an open port scan to identify exposed attack surfaces and use a WHOIS lookup to vet suspicious recruiter domains impersonating trusted employers. Job seekers in defense and aerospace should run a privacy checkup to ensure their professional profiles aren't leaking information useful to threat actors, and verify any recruiter's identity through official corporate channels before opening attachments.