[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms-mst0sun1":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"1975bd11-ac96-45f8-a0ca-bd259297cc61","Lazarus hackers exploited Windows zero-day to target defense firms","lazarus-hackers-exploited-windows-zero-day-to-target-defense-firms-mst0sun1","Lazarus Group is actively exploiting Windows zero-day CVE-2026-68820 to target defense, aerospace, and aviation firms worldwide. The vulnerability enables privilege escalation to SYSTEM level and is being weaponized alongside a new backdoor called Troy. Compromised Roundcube instances have also been seeded with RelayShell PHP web shells for persistence.","critical","advisory",[12],"CVE-2026-68820",[14,15,16,17],"Windows 11","Roundcube","Microsoft","Check Point","Immediately scan all Windows systems for exploitation of CVE-2026-68820 and check for Troy backdoor artifacts and RelayShell web shells on Roundcube servers. Block known Lazarus IOCs and monitor defense\u002Faerospace networks for lateral movement and C2 communications.",[20],"dd406f02-e7db-426d-9a27-152dd3c4a0aa",null,[23],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Flazarus-hackers-exploited-windows-zero-day-to-target-defense-firms\u002F","active","2026-08-16T14:06:15.437+00:00","2026-08-14T14:06:20.762312+00:00","2026-08-14T14:07:01.268722+00:00",[29],{"id":20,"title":6,"url":23}]