New Delhi, Aug. 12 -- REDMOND, Wash. - On the morning Microsoft released its August 2026 Patch Tuesday, the update contained a fix for a vulnerability that North Korean state hackers had already been using for weeks. The patch was one of 400. The exploit was in the wild.

Researchers at Check Point Research confirmed Tuesday that Lazarus Group, the hacking collective controlled by North Korea's Reconnaissance General Bureau, had been actively exploiting a previously undisclosed flaw in the Windows Ancillary Function Driver for WinSock - a low-level networking component present in virtually every modern Windows installation - to deliver FudModule, a kernel-mode rootkit designed to disable security software at its foundation. The flaw, trac...