Kryptovalutaticker:
sysadmin från Cyber Security News

Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

Guru Baran
9 hours ago
15 Visningar
0 Kommentarer
Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

North Korea’s Lazarus group has been caught exploiting a Windows kernel 0-day vulnerability to deploy an upgraded version of its notorious FudModule rootkit, according to new research from Check Point Research. The flaw, now tracked as CVE-2026-68820, lives inside AFD.sys, the Ancillary Function Driver that manages network sockets deep within the Windows kernel. Microsoft patched the bug on August 11 as part of its August Patch Tuesday release, just days after Check Point’s responsible disclosure. The discovery is part of a broader investigation into a fresh wave of Operation Dream Job, a long-running espionage campaign Check Point has tracked since early 2026. This latest iteration zeroes in on the defense, aerospace,...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!