BleepingComputer reports that the Lazarus group exploited a Windows zero-day in attacks against defense firms.