Overview
- Security firm Check Point attributes a fresh wave of Operation Dream Job intrusions to the North Korea‑linked Lazarus Group that used fake recruiter lures to get initial code running on victims.
- Microsoft released a Patch Tuesday fix for CVE-2026-68820 on Tuesday, Aug. 11, and CISA added the bug to its Known Exploited Vulnerabilities list, prompting agencies and defenders to patch fast.
- Researchers documented two parallel delivery chains: a DLL sideloading path that runs the in-memory MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that launches the new Troy backdoor.
- After local code execution the attackers used CVE-2026-68820, a use‑after‑free in the Windows AFD.sys driver, to escalate to SYSTEM and deploy FudModule v3.1, a kernel rootkit that disables telemetry and tampers with Smart App Control.
- Operators hid command traffic on compromised Roundcube and CMS servers using a new PHP webshell called RelayShell and abused top-ranked spoofed vendor sites, so defenders are urged to apply the patch, hunt IOCs, verify downloads through vendor channels, and treat unsolicited recruiter requests as high risk.