Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)

• 42 Critical • 355 Important • 1 Moderate • 0 Low Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild. Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.

·Tenable Blog
Read →
Vulnerabilities & Patches
Emerging2 srcs

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Key Points • Check Point Research is tracking a long‑running campaign called Operation Dream Job , targeting organizations worldwide, with a particular focus on the defense sector. The campaign is affiliated to DPRK-linked  Lazarus group  and its latest wave focuses on the defense sector in Europe and India. • In the latest variant of the Operation Dream Job campaign, the threat actor distributed  SecurityPDF , a modified PDF viewer designed to open attacker-crafted PDF documents and execute a new backdoor which we named  Troy . • During the intrusion, the threat actor exploited  CVE-2026-68820 , a zero-day vulnerability in the Microsoft  AFD.sys  driver, to deploy a new version of  FudModule , Lazarus’ kernel-mode rootkit. Following Check Point Research responsible disclosure, Microsoft released a patch as part of their August Patch Tuesday updates.

·Check Point Research
Read →
Vulnerabilities & Patches
Emerging1 src

Microsoft Patch Tuesday Update August 2026 – 394 Vulnerabilities Fixed, Including 3 Zero-Days

Microsoft has released its August 2026 Patch Tuesday security updates, addressing a massive 394 vulnerabilities across Windows, Microsoft Office, SharePoint Server, Azure services, .NET, PowerShell, Visual Studio Code, and other enterprise products. The security release, published on August 11, 2026, also includes fixes for three zero-day vulnerabilities, making prompt patching a critical priority for organizations and individual users. CVE Affected component Impact Severity Publicly disclosed Exploited in the wild CVE-2026-72971 Windows Container Isolation FS Filter Driver ( unionfs.sys ) Tampering Important Yes No CVE-2026-62832 Windows User Profile Service Elevation of Privilege Important Yes No CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Important No Yes CVE-2026-72971 affects the unionfs. sys driver used by Windows Container Isolation.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability • CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability • CVE-2026-72898 Metabase SQL Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-68820 - Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

·CISA KEV
Read →

You've reached the end of current stories for this search.