A Windows zero-day already used by North Korean-linked hackers
Microsoft's August 2026 Patch Tuesday fixed over 400 vulnerabilities, including a Windows Sockets driver zero-day that was already being exploited to seize full system control. Check Point says North Korean-linked hackers used it in a fake job-offer hacking campaign.
Microsoft's August 2026 Patch Tuesday fixed more than 400 vulnerabilities in one release, including a zero-day in the Windows Sockets driver (afd.sys) that attackers were already exploiting before the patch existed. The use-after-free bug lets a locally run program trigger a race condition and gain full SYSTEM privileges, no user interaction required. Check Point researchers say North Korean-linked hackers used this exact flaw to install a kernel-mode rootkit, delivered through a fake job-offer campaign. It is the fourth afd.sys zero-day exploited since 2022, with one earlier case tied to the Lazarus hacking group. The August update closes this hole, but only for machines that install it.