State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
Check Point, Tuesday, August 11th, 2026
Check Point details a Lazarus-linked campaign exploiting an undisclosed Windows zero-day via fake job offers.
Check Point Research describes a new wave of Operation Dream Job, the long-running campaign attributed to the North Korea-affiliated Lazarus group. The attack begins with an approach from a recruiter offering a role at a recognisable company, accompanied by a convincing PDF describing the position.
The latest wave carries a previously undisclosed Windows vulnerability, CVE-2026-68820, alongside a newly identified backdoor.
Check Point notes this recruitment lure remains one of the most effective entry points used by state-sponsored threat actors. Researchers have spent recent months tracking the campaign.