← Back to Feed

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

August 12, 2026 · The Record · Severity: HIGH

The Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies two weeks to patch a Microsoft vulnerability exploited by North Korean hackers. The bug was uncovered by researchers analyzing a persistent campaign that used fake job applications to target victims. The directive aims to prevent further exploitation of the flaw in government networks.

Key Takeaways

  • CISA orders federal agencies to patch a Microsoft bug within two weeks.
  • The vulnerability was exploited by North Korean hackers in a long-running campaign.
  • Researchers discovered the bug while investigating job application phishing attacks.
☕ Buy a Coffee