As cited
Citation snapshot as of .
vulnerabilities
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
Check Point Research documented Operation Dream Job, a Lazarus-affiliated campaign targeting defense and aerospace sectors globally through fake job offers and trojanized PDF viewers. The campaign deployed new malware including the Troy backdoor and exploited CVE-2026-68820, a zero-day in Windows AFD.sys driver, to escalate privileges using an updated FudModule rootkit; Microsoft patched the vulnerability on August 11, 2026. The threat actors compromised Roundcube webmail and other web servers to establish command-and-control infrastructure, leveraging a previously undocumented PHP webshell called RelayShell to relay traffic and maintain persistence.
Why it matters: Defense sector organizations in Europe, India, and other regions face active exploitation via spear-phishing and SEO-optimized fake vendor websites; patching CVE-2026-68820 immediately is critical, and Roundcube administrators should audit for CVE-2025-49113 exploitation and unauthorized RelayShell webshells.
- Source published
- First seen by Cybersecurity Tracker