{"id":590984,"date":"2026-08-12T13:40:08","date_gmt":"2026-08-12T13:40:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/590984\/"},"modified":"2026-08-12T13:40:08","modified_gmt":"2026-08-12T13:40:08","slug":"cisa-gives-federal-agencies-two-weeks-to-patch-microsoft-bug-exploited-in-dprk-campaign","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/590984\/","title":{"rendered":"CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign"},"content":{"rendered":"<p class=\"paragraph\"> Federal agencies were ordered to patch a Windows vulnerability used by North Korean hackers to target people applying to jobs in the defense and aerospace industry.\u00a0 <\/p>\n<p class=\"paragraph\"> The Cybersecurity and Infrastructure Security Agency (CISA) and Microsoft <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/08\/11\/cisa-adds-three-known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">confirmed<\/a> on Tuesday that CVE-2026-68820 is being exploited. The bug was the only vulnerability in Microsoft\u2019s <a href=\"https:\/\/x.com\/msftsecresponse\/status\/2087223927307440403\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Patch Tuesday release<\/a> that the company confirmed is being used in real-world attacks.\u00a0 <\/p>\n<p class=\"paragraph\"> The vulnerability impacts Winsock, a tool that acts as a bridge allowing web browsers to connect to the internet.\u00a0 <\/p>\n<p class=\"paragraph\"> Nightwing&#8217;s Nick Carroll compared the bug, which carries a seven out of ten severity score, to an intruder slipping through a closing door to print their own all-access VIP badge for a secure facility. <\/p>\n<p class=\"paragraph\"> CISA gave federal agencies until August 25 to patch the bug. A device restart is required and there is no workaround to the issue. Automox CTO Jason Kikta noted that the same component was previously exploited in 2024 by the Lazarus Group, an infamous hacking operation run out of North Korea\u2019s Reconnaissance General Bureau.\u00a0 <\/p>\n<p class=\"paragraph\"> Kikta said the vulnerability requires two steps: an attacker would need to phish their way into a low-privileged foothold before using it.\u00a0 <\/p>\n<p class=\"paragraph\"> \u201cTreat this as the month&#8217;s deadline item. It&#8217;s the one confirmed-exploited bug in the release, and it applies to every Windows endpoint you manage. Put the noise to work. This exploitation pattern is detectable, but only if your detection actually covers kernel-driver race abuse,\u201d Kikta added.\u00a0 <\/p>\n<p>Operation \u2018Dream Job\u2019<\/p>\n<p class=\"paragraph\"> Check Point said it disclosed the bug to Microsoft after discovering it as part of its examination into the latest wave of attacks that are part of <a href=\"https:\/\/therecord.media\/chemical-sector-targeted-by-north-korea-linked-hacking-group-researchers-say\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">Operation \u2018Dream Job\u2019<\/a> \u2014 a long-running campaign by North Korean hackers to exploit the job application process.\u00a0 <\/p>\n<p class=\"paragraph\"> A Check Point report <a href=\"https:\/\/blog.checkpoint.com\/research\/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">released<\/a> on Tuesday said Lazarus Group hackers impersonated recruiters for Lockheed Martin and privacy-tech firm Enveil, contacting people on LinkedIn and other sites before sending candidates malicious PDF files. Once the files are opened, a backdoor is enabled that provides Lazarus hackers with long term remote access.\u00a0 <\/p>\n<p class=\"paragraph\"> Check Point researchers explained that the malware first gathers information about the infected device before deploying an exploit for CVE-2026-68820.\u00a0 <\/p>\n<p class=\"paragraph\"> They initially thought the issue was related to a past vulnerability fixed last year but further testing proved it was a new bug. The flaw \u201callows an attacker who has already gotten malware onto a machine to escalate from limited access to complete control of it, the kind of control normally reserved for the operating system itself.\u201d <\/p>\n<p class=\"paragraph\"> Sergey Shykevich, director of threat intelligence at Check Point, said what made the campaign dangerous is not just the zero-day vulnerability but Lazarus\u2019 ability to weave legitimate, trusted infrastructure into every stage of the attack.\u00a0 <\/p>\n<p class=\"paragraph\"> \u201cThey hid in plain sight, behind top-ranked search results, real vendor branding, and the reputation of organizations they had already compromised,\u201d he said. \u201cWhen the website, the download and the recruiter all appear authentic, the old advice to &#8216;spot the phishing link&#8217; is no longer easily applicable.\u201d <\/p>\n<p class=\"paragraph\"> The researchers found targets spanning several defense sectors \u2014 including surveillance sensors, drones and robotics \u2014 in France, Germany, Brazil and India.\u00a0 <\/p>\n<p class=\"paragraph\"> Threat researchers at several companies have been <a href=\"https:\/\/therecord.media\/north-korean-hackers-target-employees-of-news-outlets-software-vendors-and-more-through-chrome-vulnerability\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">tracking<\/a> the Operation DreamJob campaign since 2020. Google <a href=\"https:\/\/therecord.media\/north-korean-hackers-target-employees-of-news-outlets-software-vendors-and-more-through-chrome-vulnerability\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">warned in 2022<\/a> that 250 people working for 10 different news media, domain registrars, web hosting providers and software vendors were targeted by the campaign, receiving malicious emails from fake recruiters claiming to be from Disney, Google and Oracle.\u00a0 <\/p>\n<p class=\"paragraph\"> ESET previously <a href=\"https:\/\/therecord.media\/north-korea-hackers-target-europe-drone-makers\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">tracked<\/a> compromises related to the campaign in India, Poland, the U.K. and most recently Italy.\u00a0 <\/p>\n<p class=\"paragraph\"> CISA\u2019s decision to order federal agencies to patch the bug comes after FBI officials <a href=\"https:\/\/federalnewsnetwork.com\/technology-main\/2026\/08\/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">said<\/a> they are currently investigating an incident where an unidentified federal agency mistakenly hired an IT worker from North Korea as part of the country\u2019s <a href=\"https:\/\/therecord.media\/north-korea-it-worker-scheme-expands-outisde-us-tech\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">long-running campaign<\/a> to infiltrate organizations globally.  <\/p>\n<p>Get more insights with the <\/p>\n<p>Recorded Future<\/p>\n<p>Intelligence Cloud.<\/p>\n<p><a class=\"underline\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" href=\"https:\/\/www.recordedfuture.com\/platform?mtm_campaign=ad-unit-record\">Learn more.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Federal agencies were ordered to patch a Windows vulnerability used by North Korean hackers to target people applying&hellip;\n","protected":false},"author":2,"featured_media":590985,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[61,60,80],"class_list":["post-590984","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ie","tag-ireland","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/590984","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=590984"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/590984\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/590985"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=590984"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=590984"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=590984"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}