<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Lazarus-Group on CuraSec</title><link>https://curasec.metacog.co.kr/tags/lazarus-group/</link><description>Recent content in Lazarus-Group on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 13 Aug 2026 11:57:16 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/lazarus-group/index.xml" rel="self" type="application/rss+xml"/><item><title>Lazarus Exploits Patched Windows Zero-Day for SYSTEM Access via Dream Job</title><link>https://curasec.metacog.co.kr/insights/2026-08-13-lazarus-exploits-windows-zero-day-to-gain-system-access-and/</link><pubDate>Thu, 13 Aug 2026 11:57:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-13-lazarus-exploits-windows-zero-day-to-gain-system-access-and/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A nation-state actor achieved SYSTEM-level privilege escalation via an actively exploited Windows zero-day — patch the now-available Microsoft fix across all Windows endpoints immediately, prioritizing internet-facing and privileged systems.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Operation Dream Job is an active Lazarus campaign with a novel backdoor; pull Check Point&amp;rsquo;s research for IOCs and behavioral signatures, then hunt for related artifacts on endpoints in your estate since the campaign&amp;rsquo;s known timeframe, especially if you defend defense or aerospace clients.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your organization operates in defense or aerospace, brief leadership on Lazarus targeting and verify whether your threat intelligence program covers nation-state espionage campaigns at this tier; confirm your security team has applied the Windows patch and is hunting for the associated backdoor.&lt;/li>
&lt;/ul></description></item></channel></rss>