Suzanne Kantra/Techlicious generated by ChatGPT
Microsoft released its monthly security update yesterday, and one of the fixes closes a hole that hackers were already using to break into Windows computers. Security firm Check Point says the attacks come from Lazarus, a hacking group tied to North Korea. It is the latest version of a campaign of similar attacks dubbed Operation Dream Job, which security researchers have been tracking for years.
According to Check Point, this new campaign "focused heavily on the defense sector, particularly organizations involved in military technologies such as surveillance sensors, drones, and robotics." The scheme begins with a fake job offer: a recruiter reaches out about a role at a company the target would recognize and sends a PDF describing the position. Opening that PDF leverages a Windows system flaw to take full control of the machine.
The flaw sits in the Windows Ancillary Function Driver for WinSock, a system-level driver that manages network connections. An attacker who already has a foothold in your PC can exploit the bug to grant themselves SYSTEM privileges, the highest level of Windows access. Microsoft hasn't said whether the flaw has been used in attacks beyond the one Check Point identified.
Windows normally downloads security patches automatically, but you can check yourself and install it manually, if needed. Open Settings, go to "Windows Update," and select "Check for updates." If an update is ready, install it and restart your PC.
Read next: What's still risky about public Wi-Fi