Microsoft's August advisory attributes active exploitation of a Windows zero-day to Lazarus Group, the North Korean state-linked operator, delivering a backdoor Microsoft has not seen before. The company's write-up frames the flaw as newly patched. The exploitation window runs the other direction: Lazarus had working code before Microsoft had a fix, which is the normal order for a zero-day and the reason "patched" and "safe" are not the same word this week for any Windows fleet that has not yet applied the update.
The same week carries a second zero-day, "LegacyHive," disclosed after July's Patch Tuesday and now patched by Microsoft on a separate track from the Lazarus flaw. Two unrelated zero-days landing in the same disclosure cycle is not evidence of a pattern, it is evidence that Patch Tuesday is a scheduling artifact, not a security boundary. The control that matters here is emergency out-of-band patching for both CVEs ahead of the next scheduled cycle, not the calendar Microsoft happens to publish on.