Lazarus-linked attacks exploit Windows CVE-2026-68820 as a zero-day to gain SYSTEM access and deploy Troy against defense and aerospace firms.

Microsoft patches 398 flaws, including exploited CVE-2026-68820 that lets local attackers reach SYSTEM, plus four unauthenticated 9.8 RCEs.

Microsoft has released a patch for a Windows use-after-free zero-day vulnerability already being exploited to deploy malware used by the Lazarus hacking group.