Close Menu
The Financial News 247The Financial News 247
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
What's On

OPEC+ keeps oil output policy unchanged for October 

September 6, 2026

Lululemon billionaire founder Chip Wilson files for divorce after 20 years of marriage — with no prenup in place

September 5, 2026

Marmalade Cafe files for Bankruptcy after closing Calabasas location

September 5, 2026

Stunt Performer Jahnel Curfman On Recent Emmy Nomination, Motherhood And Success In A Male-Dominated Industry

September 4, 2026

Who Really Owns AI? What The CAIO Surge Means For CTOs

September 4, 2026
Facebook X (Twitter) Instagram
The Financial News 247The Financial News 247
Demo
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
The Financial News 247The Financial News 247
Home » Microsoft Windows 0-Day Attack Deploys Lazarus Rootkit—Patch Now

Microsoft Windows 0-Day Attack Deploys Lazarus Rootkit—Patch Now

By News RoomAugust 12, 2026No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Telegram Reddit Email Tumblr
Share
Facebook Twitter LinkedIn Pinterest Email

It’s not just Google that has a problem with use-after-free memory vulnerabilities; Microsoft has released a patch for such a zero-day issue that is already being exploited in the wild by attackers to deploy malware used by the North Korean hacking group known as Lazarus. CVE-2026-68820, the security vulnerability in question, sits in the WinSock ancillary function driver for WinSock. The high-rated vulnerability, that Microsoft said “allows an authorized attacker to elevate privileges locally” and gain system privileges, was disclosed by Check Point Research after observing it being used to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit.

Given that exploits are already being tracked, with the Cybersecurity and Infrastructure Security Agency adding CVE-2026-68820 to its Known Exploited Vulnerabilities database on August 11, users are advised to prioritize patching this issue.

Microsoft Fixes 421 Vulnerabilities With August 2026 Patch Tuesday Security Update

Microsoft has not bucked the trend of disclosing and patching large numbers of vulnerabilities in regular security updates that has been evident across vendors such as Google and Oracle this year so far. The August 2026 Patch Tuesday update has covered no less than 421 vulnerabilities in all, including three zero-days, of which CVE-2026-68820 is the only one listed as already being confirmed exploited.

Mike Walters, co-founder of Action1, has warned that a locally authenticated attacker with low privileges could “run a specially crafted application and trigger a race condition,” leading to privilege escalation and the potential to obtain “extensive control over the affected Windows system.” Which is why the confidentiality, integrity, and availability impacts of CVE-2026-68820 are all rated High. Deployment of the update patch “should be prioritized even though the vulnerability is rated important rather than critical,” as a result, Walters concluded.

“The ebb and flow of the ‘Patch Apocalypse’ continues with no sign of slowing yet,” Todd Schell, principal product manager at Ivanti, said. The problem is that not all Common Vulnerabilities and Exposures are created equal. “The patches need to be triaged to identify those CVEs that require immediate attention, including those tied to known exploitation or disclosure, known malware, CISA’s KEV list, or internet-facing or unauthenticated vulnerabilities,” Schell warned, but you need to remain disciplined and remember even CVEs with high CVSS scores which are not exploited or are not internet-facing can be handled in a second round of patching.” CVE-2026-68820 should, therefore, be on your priority list if you are a user of the impacted platforms. And that list is long: Microsoft Windows 10, Windows 11, Windows Server 2012, 2016, 2019, 2022 and 2025.

CVE-2026-68820 Patch Tuesday August 2026 Windows Windows Security Update Windows Update Windows Zero Day Attack
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

Who Really Owns AI? What The CAIO Surge Means For CTOs

September 4, 2026

Why Most Enterprise AI Programs Stall Before They Scale

September 4, 2026

How Technology Can Improve Public Safety Without Invading Privacy

September 4, 2026

The Payment That Never Arrives

September 4, 2026

AI Transformation Is An Organization Redesign Project

September 4, 2026

Welcome To The Cyber Compliance Cascade

September 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

Lululemon billionaire founder Chip Wilson files for divorce after 20 years of marriage — with no prenup in place

Business September 5, 2026

Lululemon’s billionaire founder Chip Wilson is divorcing his wife of 20 years — without a…

Marmalade Cafe files for Bankruptcy after closing Calabasas location

September 5, 2026

Stunt Performer Jahnel Curfman On Recent Emmy Nomination, Motherhood And Success In A Male-Dominated Industry

September 4, 2026

Who Really Owns AI? What The CAIO Surge Means For CTOs

September 4, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

America’s population of 401(k) millionaires hits record high

September 4, 2026

Lululemon shares plunge 18% as retailer slashes outlook ahead of CEO handoff

September 4, 2026

Why Most Enterprise AI Programs Stall Before They Scale

September 4, 2026

OpenAI CEO Sam Altman says 38K ChatGPT queries only use amount of water it takes to grow an almond

September 4, 2026
The Financial News 247
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us
© 2026 The Financial 247. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.