421 bugs in Microsoft’s Patch Tuesday release, and the Norks have already attacked one

That is an epic month for Microsoft patches, although not a record-setting one. Redmond addressed 421 bugs in its personal merchandise this month – about 200 fewer CVEs than last month, however likely the new norm with AI-assisted vulnerability disclosures and fixes

The massive information is that North Korea’s Lazarus Group (and probably different miscreants) discovered and attacked one in all these flaws as a zero-day in early June.

The bug, tracked as CVE-2026-68820, is a use-after-free within the Home windows Ancillary Perform Driver for WinSock. “A regionally authenticated attacker may run a specifically crafted utility on an affected system to set off a race situation,” Redmond warned, including that profitable exploitation may enable an attacker to execute code with SYSTEM-level privileges, and with no person interplay required.

Microsoft credited Test Level researchers Moshe Marelus and David Driker with discovering and reporting CVE-2026-68820, and the safety store’s risk intel lead informed us that his analysts first noticed attackers – particularly North Korea’s Lazarus Group – battering this CVE originally of June.

“We’re accustomed to one profitable implementation of the CVE – however we assume it was used extensively within the marketing campaign,” Sergey Shykevich, director of risk intelligence at Test Level, informed The Register.

He’s speaking about Operation Dream Job, a long-running marketing campaign focusing on organizations worldwide, particularly these within the protection sector, and attributed to Lazarus, an umbrella time period for Pyongyang’s government-sponsored goons who focus on cryptocurrency theft, extortion assaults, and IT worker scams

It’s in all probability finest identified for the Sony Pictures Entertainment hack in late 2014 and the WannaCry ransomware outbreak in 2017, though the group has been energetic since a minimum of 2009. 

Lazarus’ DreamJob campaigns have been around since 2020, they usually use social engineering to lure job seekers with pretend presents for high-profile positions, then trick the victims into clicking on malicious hyperlinks or opening malware-laced paperwork. The aim in these assaults entails stealing IP and different delicate information, conducting cyber spying missions, and accumulating monetary info.

When Dream Job and Patch Tuesday collide

This new wave of assaults focuses on the protection sector in Europe and India with dream jobs impersonating Lockheed Martin and privacy-tech agency Enveil. Attackers created a minimum of three pretend Enveil websites, and a few even ranked as the highest search outcome, making them much more plausible to job seekers – and more durable to identify a phish. 

“On this marketing campaign, the risk actor expanded its supply technique by leveraging impersonation web sites and SEO (search engine marketing) strategies to distribute the trojanized functions, rising its credibility and serving to it evade some phishing-based detections,” Test Level researchers said in a Tuesday weblog.

These assaults contain Lazarus distributing a modified PDF viewer known as SecurityPDF designed to execute malicious payloads embedded inside attacker-crafted PDF information when the person opens them. The PDFs, when opened, execute a never-before-seen backdoor that Test Level named Troy.

And through the intrusions, the Norks exploited CVE-2026-68820 as a zero-day to deploy a brand new model of FudModule, Lazarus’ kernel-mode rootkit. 

“We won’t be disclosing full technical particulars of the vulnerability on this article, because it was patched on the August 11 Patch Tuesday repair,” the researchers wrote. “At a excessive stage, the exploit takes benefit of how afd.sys handles a socket is created when it’s accessed concurrently by a number of threads without delay.”

Shykevich informed us that “this marketing campaign reveals that this actor continues to develop new instruments (like Troy), and discovering and implementing new vulnerabilities in Home windows to evade detection.”

Better of the remainder

Redmond lists one of many different 421 Microsoft CVEs as publicly identified. It’s CVE-2026-62832, an elevation-of-privilege flaw, and the Home windows large says exploitation is “extra seemingly,” so patch this one sooner.

“An authenticated attacker who has credentials for an additional native account may run a specifically crafted utility to load one other person’s registry hive,” in line with the safety advisory. “Profitable exploitation may enable the attacker to entry or modify one other person’s information and acquire administrator privileges. Person interplay shouldn’t be required.”

Whereas CVE-2026-68820 and CVE-2026-62832 are the one vulnerabilities that Microsoft considers “notable” in its August patch cycle, Pattern Micro’s Zero Day Initiative highlights five others, together with one which got here via ZDI’s bug reporting program and one other that was efficiently exploited at ZDI’s Pwn2Own contest in Berlin. All 5 of those must be thought-about notable and exploitable, so give these a learn, too.

CVE-2026-62893, a crucial flaw in Home windows Deployment Companies TFTP Server that results in distant code execution with out person authentication or person interplay, is the one disclosed via ZDI. “TFTP has no auth mechanism and is obtainable remotely vid UDP port 69,” ZDI bug boss Dustin Childs wrote. “UDP port 69 must be blocked at your perimeter, however this might simply be utilized by attackers for lateral motion inside an enterprise. Once more, check and deploy this one rapidly in case you’re utilizing WDS for deployments in your enterprise.”

In the meantime, CVE-2026-62911, one of many many Change bugs on this month’s launch, was demonstrated at ZDI’s Pwn2Own in Berlin. It permits a privilege escalation by way of an authentication bypass, and exploitation would enable an attacker to “take over the mailboxes of all Change customers, attackers can ship emails, learn emails, obtain attachments,” in line with Microsoft, which oddly deemed “exploitation much less seemingly.”

Childs calls BS on this. “Ignore Microsoft’s exploitability and Exploit Code Maturity scores,” he wrote.

“We handed them working exploits, so this can be a actual risk.” ®

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *