← Back to Feed
CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
August 12, 2026 · The Record · Severity: HIGH
The Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies two weeks to patch a Microsoft vulnerability exploited by North Korean hackers. The bug was uncovered by researchers analyzing a persistent campaign that used fake job applications to target victims. The directive aims to prevent further exploitation of the flaw in government networks.
Key Takeaways
- CISA orders federal agencies to patch a Microsoft bug within two weeks.
- The vulnerability was exploited by North Korean hackers in a long-running campaign.
- Researchers discovered the bug while investigating job application phishing attacks.