Lazarus Group used Windows zero-day and quantum encryption to hit defense firms

4 sources
  • Lazarus Group exploited a Windows zero-day (CVE-2026-68820) to gain full system control at defense and aerospace firms in France, Germany, Brazil, and India, according to Check Point Research.
  • The hackers used quantum-resistant encryption to conceal exploit delivery and posed as recruiters for Lockheed Martin and Enveil in their long-running Operation Dream Job campaign.
  • CISA ordered federal agencies to patch by Aug. 25 after Microsoft fixed the flaw, which had been actively exploited for roughly five weeks.
Sources (4)
  1. 1 North Korea's Lazarus Hides Windows Zero-Day Behind Quantum-Grade Encryption to Hit Defense Firms – SOFX www.sofx.com
  2. 2 Lazarus hackers exploited Windows zero-day to target defense firms www.bleepingcomputer.com
  3. 3 North Korean Hackers Use Fake Job Offers And Windows Bug To Attack Defence Firms www.etvbharat.com
  4. 4 North Korean hackers turn LinkedIn into a hunting ground cybernews.com