A Busy Week for Windows Security Teams
The latest LeakWatch roundup for calendar week 33 of 2026 packs a lot into one report: an actively exploited Windows zero-day, fresh hardware-level flaws in AMD and Intel chips, and two malware families making the rounds. If you manage Windows PCs at home or at work, this is the kind of week where patching cannot wait for the next quiet weekend.
The headline item is CVE-2026-68820, a Windows vulnerability that attackers are already using in the wild. LeakWatch's assessment ties it together with hardware-adjacent issues in AMD's firmware-based Trusted Platform Module (fTPM) and separate Intel vulnerabilities, plus activity from ransomware operation Gunra and a newer strain called WindRelay. None of these threats exist in isolation. Together they describe a layered attack surface: get in through a software bug, dig deeper using weaknesses tied to the hardware, then deploy malware once inside.
What CVE-2026-68820 Is and Why It's Being Actively Exploited
CVE-2026-68820 is an elevation-of-privilege vulnerability. In plain terms, it lets an attacker who already has some foothold on a machine, even a limited one, escalate to much higher system permissions. That distinction matters. Elevation-of-privilege bugs rarely make headlines the way remote-code-execution flaws do, but they are exactly the kind of vulnerability that turns a minor compromise into full control of a device.
What makes this one urgent is that it is not theoretical. LeakWatch confirms active exploitation, meaning real attackers are using it against real targets right now, not just researchers demonstrating proof-of-concept code. Our earlier reporting on CVE-2026-68820 and its ties to the AFD.sys driver in Windows 11 goes deeper into the technical mechanics of how the flaw is being abused, including its connection to the state-linked Lazarus group, which has a track record of pairing Windows zero-days with social engineering, including fake job offer schemes designed to get malicious code onto a victim's machine in the first place.
How the AMD-fTPM and Intel Flaws Compound the Risk
What sets this week's LeakWatch report apart from a routine patch advisory is the hardware angle. AMD-fTPM implements Trusted Platform Module functionality in firmware rather than a dedicated chip, and it is relied on for things like disk encryption keys and secure boot verification. A flaw here does not just affect one application; it can undermine the trust anchor that other security features depend on. LeakWatch also flags separate Intel vulnerabilities in the same assessment window.
The practical concern is layering. A Windows privilege escalation bug like CVE-2026-68820 gives an attacker a way in and up. A weakness in fTPM or Intel firmware can give that same attacker a way to persist more deeply, potentially surviving reinstalls or evading detection tools that assume the hardware root of trust is solid. Individually, each flaw is serious. Combined, they describe an attack chain that moves from operating system to firmware, which is much harder for ordinary security tools to catch.
Gunra and WindRelay: What They Do Once Inside
Once attackers have elevated access, they need a payload, and that is where Gunra and WindRelay come in. Gunra operates as a ransomware threat, encrypting or exfiltrating data for extortion, a business model that has become the default for cybercriminal groups in recent years, as seen with other ransomware-as-a-service operations like Eclipse that lower the barrier to entry for affiliates. WindRelay is flagged as a newer malware family in the same report, and its emergence alongside an actively exploited zero-day is a reminder that criminal groups move quickly to capitalize on fresh vulnerabilities before defenders finish patching.
This pairing of a privilege-escalation bug with ransomware deployment is not new territory. Attackers have shown similar patterns before, including credential theft campaigns run through compromised Wi-Fi networks that give them the initial access needed before deploying further tools. The common thread is always the same: get a foothold, escalate privileges, then monetize the access.
Immediate Steps to Protect Your Windows PC This Week
You do not need to be a security professional to reduce your exposure this week. Here is a practical checklist:
- Install the latest Windows security updates as soon as possible. Microsoft's Patch Tuesday cycle has already addressed CVE-2026-68820 alongside hundreds of other fixes; delaying the install window leaves the door open.
- Check for firmware and BIOS updates from your PC manufacturer, particularly if your system uses AMD or Intel processors covered by the flaws mentioned this week.
- Enable automatic updates for Windows and your antivirus or endpoint protection tool so future critical patches deploy without manual intervention.
- Back up important files to an offline or cloud location that is not permanently connected to your main device, which limits the damage ransomware like Gunra can do.
- Be skeptical of unsolicited job offers, recruiter messages, or unexpected attachments, a common delivery method for the kind of zero-day exploitation described here.
What This Means For You
For most home users and small businesses, the takeaway is not panic, it is prompt action. Actively exploited vulnerabilities like CVE-2026-68820 are dangerous precisely because attackers already know how to use them while many systems remain unpatched. The added complexity of AMD-fTPM and Intel firmware issues means that even after you patch Windows itself, checking for firmware updates matters more than it usually would. And with ransomware groups like Gunra and new malware like WindRelay ready to move in once access is gained, the difference between a routine patch Tuesday and a costly incident often comes down to how quickly updates get applied.
Final Takeaways
This week's LeakWatch findings underscore a pattern worth remembering: software and firmware vulnerabilities rarely stay separate from the malware that exploits them. Treat the Windows zero-day CVE-2026-68820 patch as a priority, not an optional update, and pair it with a firmware check for AMD and Intel systems. Keep backups current, stay alert to phishing-style lures, and make sure automatic updates are actually turned on. None of these steps require advanced technical skill, but together they close the exact gaps that this week's threats are built to exploit.




