Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)
ID: 0151f823-1677-5d55-9a55-aec544ef5c9f
STIX ID: report--0151f823-1677-5d55-9a55-aec544ef5c9f
Feed Name: Help Net Security
Threat Score
Microsoft's August 2026 Patch Tuesday fixed 400+ vulnerabilities, notably CVE-2026-68820 — a Windows AFD.sys use-after-free that has been exploited by North Korean actors as part of the Operation Dream Job campaign to deploy a kernel-mode rootkit — plus several publicly disclosed critical flaws and unauthenticated remote code execution vulnerabilities; the report also notes a proof-of-concept that bypasses a recent Microsoft Defender patch and advises cautious, triaged patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
