Breaking: North Korean Zero-Day + VMware vCenter Under Active APT Exploitation — 17 August 2026
North Korean Lazarus Group Exploits Windows Zero-Day in Defense Sector Campaign
CISA has issued an Emergency Directive ordering federal agencies to patch CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), within 14 days. The flaw, disclosed as part of Microsoft's August 2026 Patch Tuesday, carries a CVSS score of 7.0 but has been confirmed as actively exploited in the wild by North Korea's Lazarus Group as part of Operation Dream Job.
Operation Dream Job is a long-running social engineering campaign where Lazarus operatives impersonate recruiters from companies including Lockheed Martin and privacy-tech firm Enveil, contacting targets on LinkedIn before sending malicious PDF files. Once opened, the documents deploy a backdoor that gathers device information before exploiting CVE-2026-68820 to escalate privileges from limited access to SYSTEM-level control — the highest privilege level in Windows. The same afd.sys component was previously exploited by Lazarus in 2024.
Check Point, which disclosed the vulnerability to Microsoft, confirmed targets spanning defence sectors including surveillance sensors, drones, and robotics in France, Germany, Brazil, and India. The campaign's danger lies not just in the zero-day itself but in Lazarus' ability to weave legitimate infrastructure into every attack stage: real vendor branding, top-ranked search results, and compromised organisations providing apparent authenticity. The FBI is separately investigating an incident where a US federal agency inadvertently hired a North Korean IT worker as part of the same infiltration strategy.
There is no workaround. A device restart is required. The CISA deadline is August 25, 2026.
VMware vCenter Under Active APT Exploitation Across 47 Countries
A critical VMware vCenter directory-traversal vulnerability, CVE-2026-59310 (CVSS 9.8), is being actively exploited by a suspected APT actor just five days after Broadcom publicly disclosed it on July 29. German incident response firm QUIRSO discovered the campaign during an engagement, finding 361 compromised server IP addresses across 47 countries, with concentrations in Germany, the US, Turkey, Iran, and France.
The attack chain shows path traversal activity consistent with CVE-2026-59310, followed by deployment of a malicious cron job that installs reverse_ssh — an open-source tool establishing outbound SSH connections to attacker-controlled infrastructure. This persistence mechanism bypasses security controls designed to block suspicious inbound requests. Every unpatched internet-facing vCenter server appears reachable and vulnerable.
Separately, Defused Cyber reports a spike in scanning targeting CVE-2026-59309 (also CVSS 9.8), an authentication bypass in vmdir, suggesting exploitation of VMware vulnerabilities may be broadening. Chinese APT group UNC5174 has previously weaponised VMware flaws in espionage campaigns, and the reverse_ssh tool overlaps with tooling used by China-nexus cluster PurpleHaze. Attribution for the current campaign remains unconfirmed.
Patches for both CVE-2026-59309 and CVE-2026-59310 were released by Broadcom in late July. If you run vCenter and have not patched, treat this as an emergency: audit for reverse_ssh binaries and unexpected cron jobs immediately, then patch.
So What / Action
Two urgent patch-or-justify items this week. The Windows Winsock elevation-of-privilege flaw is the only confirmed-exploited CVE from August Patch Tuesday, and CISA's Emergency Directive makes the August 25 deadline mandatory for federal agencies and a de facto standard for everyone else. If your organisation has any exposure to defence or aerospace supply chains, the Dream Job campaign's European targeting makes this personal. Patch all Windows endpoints and verify detection coverage for kernel-driver race condition exploitation.
For VMware vCenter: if you have not patched VMSA-2026-0006 yet, stop reading this and patch now. The five-day gap between disclosure and active exploitation, with confirmed compromises in 47 countries, means any internet-facing unpatched vCenter should be assumed compromised. Hunt for reverse_ssh binaries, unexpected cron entries, and anomalous outbound SSH connections before patching — patching a compromised system without remediation just closes the door behind the attacker who is already inside.

