Infosec News Nuggets — August 13, 2026
Brief
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
North Korea’s Lazarus Group exploited a Windows zero-day in the AFD. sys driver as part of a fresh wave of its long-running Dream Job campaign, targeting defense and aerospace firms in France, Germany, Brazil, and India with fake recruiter outreach on LinkedIn.
Victims were lured into opening a trojanized PDF viewer or a malicious archive that deployed a new backdoor called Troy, while a companion downloader used the flaw to gain SYSTEM privileges and load an updated version of the FudModule rootkit capable of tampering with Windows Smart App Control.
The campaign hijacked compromised WordPress, SharePoint, and Roundcube servers for command-and-control traffic to blend in with legitimate web activity, and the exploited flaw has since been patched in Microsoft’s August update.
