In fresh attacks, North Korean APT Lazarus has exploited CVE-2026-68820, a new Windows zero-day, to take over victims’ systems.

Microsoft has released a patch for a Windows use-after-free zero-day vulnerability already being exploited to deploy malware used by the Lazarus hacking group.

In fresh attacks, North Korean APT Lazarus has exploited CVE-2026-68820, a new Windows zero-day, to take over victims’ systems.