AU
FudModule v3.1 Zeroes the Crash Dump Block Before Anything Else
Lazarus used an actively exploited afd.sys use-after-free (CVE-2026-68820) to deploy FudModule v3.1 on Windows 11 26100 and 26200. The rootkit’s first act is killing the crash dump path, which changes the order you triage a suspected host.