Thank you for subscribing!

Hackers can delete your files, install malware, tamper with security tools, and more

A new "zero-day vulnerability" known as CVE-2026-68820 has been found to be exploiting Windows PCs. Experts say this type of flaw is extra worrisome as hackers have already discovered the glitch and will be leveraging it to hack into devices worldwide.

And this particular bug is in a networking component of Windows that lets attackers who have already gained basic access to your PC escalate their privileges to full system control. This means bad actors can view or delete your files, install malware, tamper with security tools, and essentially own your machine. If successful, they could gain ownership of your personal details — potentially impersonating you or draining your bank accounts.

Check Point Research has linked CVE-2026-68820 to North Korea's Lazarus Group, which has weaponised it as part of elaborate fake job scams targeting the defence sector.

The attackers created fake recruitment listings for firms, even manipulating Google search results so their fraudulent postings appeared right at the top.

Victims who took the bait were funnelled towards the zero-day exploit, giving hackers complete control of their machines.

Sergey Shykevich, Director of Threat Intelligence at Check Point, said: "What makes this campaign so dangerous is not only the zero-day vulnerability - but also how Lazarus wove legitimate, trusted infrastructure into every stage of the attack."

He warned that the advice about spotting dodgy links is no longer sufficient because they're getting more difficult to determine their legitimacy.

The fix for CVE-2026-68820 is available right now. To install, head to Settings, then Windows Update, and check for updates straight away. You should be able to see these updates if you have Windows 11 installed.

If you still have its predecessor, Windows 10, installed, you need to be enrolled in the free Extended Security Updates programme to keep receiving patches.

However, that's not the only flaw to be on red alert for right now. A security researcher has also published another zero-day vulnerability — this time in Windows Defender Antivirus itself.

The researcher, who goes by Nightmare Eclipse, released a flaw dubbed "ShieldBreak" that lets attackers escalate their access to full system-level privileges by exploiting Microsoft's built-in antivirus tool.

Security researchers Will Dormann and Kevin Beaumont both confirmed the exploit works. "Gets you SYSTEM privileges from any user account," Mr Beaumont said. "I've tried it, it works on the latest Windows 11."

Microsoft hasn't released a fix for this yet and hasn't yet commented publicly on the flaw. As long as Windows Defender Antivirus is enabled — which it is by default on most PCs — systems remain exposed.

Unfortunately, it’s important not to leave Windows Defender Antivirus turned off because it provides your PC with a layer of protection against malware, ransomware, spyware and other threats.

Instead, Mr Shykevich recommends patching the moment updates land and verifying software only through official channels. He said: "Staying safe now means assuming that trust itself can be counterfeited."