Microsoft released patches for 423 CVEs in the August Patch Tuesday update. The release did not include any security updates for Microsoft Edge. The author notes a change in the distribution of CWE categories represented in this month's vulnerabilities.
Microsoft
15 posts
A heap of overflow in August’s Patch Tuesday haul Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities Microsoft's August 2026 Patch Tuesday addresses 421 vulnerabilities including 62 rated critical. One vulnerability, CVE-2026-68820 (Windows Ancillary Function Driver for WinSock, CVSS 7.0), has been exploited in the wild as a local elevation of privilege flaw. Critical RCE vulnerabilities span Windows server components (DNS, DHCP, TFTP, AD CS, RRAS, SSTP, iSCSI), desktop applications (Office, Excel, SharePoint, Remote Desktop Client), and cloud services (Azure SQL, Azure Service Bus, Azure AD, Microsoft Teams). Talos released Snort rules providing network-level detection for exploitation attempts against a subset of these vulnerabilities.
Cyber Centre Daily Advisory Digest — 2026-07-23 (3 advisories) The Canadian Centre for Cyber Security published a daily digest on 2026-07-23 containing three security advisories. Check Point addressed CVE-2026-16232 (actively exploited, CISA KEV-listed) affecting Security Management and Firewall products. Microsoft's July 2026 monthly rollup covers a broad product surface with four CVEs confirmed exploited in the wild (CVE-2026-56164, CVE-2026-56155, CVE-2026-58644, CVE-2026-50522). JetBrains also released fixes for GoLand, IntelliJ IDEA, and PhpStorm prior to version 2026.2.
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities Microsoft's July 2026 Patch Tuesday discloses 622 vulnerabilities, including 57 critical-severity issues spanning RCE, elevation of privilege, spoofing, and security feature bypass across Windows components, Office, SharePoint, SQL Server, Dynamics, and cloud services. Two vulnerabilities — an AD FS elevation of privilege flaw (CVE-2026-56155) and a SharePoint spoofing flaw (CVE-2026-56164) — are confirmed exploited in the wild, and 11 critical RCE issues plus several important EoP flaws are rated 'more likely' to be exploited by Microsoft. Cisco Talos has released Snort 2 and Snort 3 rule updates to detect exploitation attempts for a subset of the disclosed vulnerabilities.
July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days Microsoft's July 2026 Patch Tuesday release addresses 622 vulnerabilities, including two actively exploited zero-days and one publicly disclosed zero-day, with 62 rated Critical. The dominant exploitation techniques this month are elevation of privilege (41%), remote code execution (27%), and information disclosure (18%), though the article provides no specific CVE identifiers, affected products, or technical exploitation details.
22nd June – Threat Intelligence Report This threat intelligence report highlights recent data breaches involving third-party vendors, emerging AI threat vectors such as prompt injection and WebSocket abuse, and active exploitation of critical vulnerabilities in Fortinet, Cisco, and Splunk products. Additionally, seasonal phishing campaigns targeting travelers and Amazon Prime members are surging alongside a cross-platform Rust-based crypto clipboard hijacker.
Cyber Centre Daily Advisory Digest — 2026-06-17 (3 advisories) The Canadian Centre for Cyber Security released a daily digest highlighting critical security updates from Oracle, JetBrains, and Microsoft. The advisories cover Oracle's June 2026 quarterly rollup affecting numerous enterprise products, a vulnerability in JetBrains GoLand, and an Elevation of Privilege flaw in the Microsoft Malware Protection Engine (CVE-2026-50656).
Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities Microsoft's June 2026 Patch Tuesday addresses 206 vulnerabilities, including 32 critical flaws primarily involving Remote Code Execution (RCE). Four critical vulnerabilities affecting the Remote Desktop Client, HTTP Protocol Stack, and Windows Graphics component are highlighted as more likely to be exploited, prompting immediate patching and the deployment of updated network intrusion rules.
Phishing for Lobsters: How We Tricked OpenClaw into Spilling Secrets Varonis Threat Labs demonstrated that enterprise AI agents, specifically an OpenClaw deployment, are vulnerable to traditional phishing and social engineering techniques. In simulated attacks, the agent successfully identified technical phishing indicators like malicious OAuth flows but failed to recognize social context, resulting in the exfiltration of AWS credentials and sensitive CRM data to an external attacker.
- 8 minWeekly Recap — 2026-05-25 -> 2026-06-01
Session Hijacking and Developer Tool Poisoning Collapse Authentication Trust This week, attackers proved that multi-factor authentication is no longer a reliable gatekeeper. Campaigns like Tycoon 2FA and Chinese-language PhaaS platforms intercept one-time passwords in real time and steal session tokens to maintain persistent access, while infostealers like EKZ Infostealer harvest browser cookies to bypass authentication entirely. Even when victims reset passwords and revoke sessions, attackers retain access through hidden device registrations — meaning standard incident response playbooks are now incomplete. Developers remain the preferred entry point for supply chain compromise. The Glassworm botnet was disrupted after hiding malware in VSCode extensions and npm packages, while the Megalodon campaign poisoned GitHub Actions workflows across 5,500 repositories. A malicious Sicoob.Sdk NuGet package stole banking certificates from Brazilian developers, and North Korea's Lazarus group compromised the widely used axios npm library — a single attack touching millions of downstream applications. Organizations must move beyond password-and-MFA reliance: adopt hardware security keys, shorten session lifetimes, delete attacker-registered devices before resetting credentials, and audit developer toolchains and CI/CD pipelines for tampering.
Top 5 Phishing-Driven Social Engineering Attacks on Companies in 2026 Modern social engineering attacks have evolved to closely mimic legitimate business workflows, utilizing techniques like ClickFix, OAuth device code abuse, and in-browser blob phishing. These tactics bypass traditional security controls and create "gray-zone" alerts that require deep behavioral analysis to determine the true scope of compromise, such as credential theft, token abuse, or RMM deployment.
May’s Patch Tuesday hauls out 132 CVEs Microsoft's May 2026 Patch Tuesday release addresses 132 CVEs, including 29 Critical vulnerabilities and 14 with a CVSS score of 9.0 or higher. Key threats include a critical authentication bypass in the Microsoft SSO Plugin for Jira & Confluence, unauthorized RCEs in Windows Netlogon and DNS Client, and multiple Office RCEs exploitable via the Preview Pane.
Intelligence Center Microsoft's May 2026 Patch Tuesday addresses 137 vulnerabilities, including 31 critical flaws, 16 of which are Remote Code Execution (RCE) vulnerabilities. While no active exploitation has been observed, critical flaws affect core services like Windows Netlogon, DNS Client, and Azure Managed Instances, prompting the release of Snort detection rules by Cisco Talos.
Microsoft addresses 163 CVEs, 88 advisories for April Patch Tuesday Microsoft's April 2026 Patch Tuesday addresses 163 CVEs across 17 product families, including 8 Critical vulnerabilities and one actively exploited zero-day (CVE-2026-32201 in SharePoint). Organizations should prioritize patching the exploited SharePoint flaw, the publicly disclosed Defender bug (CVE-2026-33825), and a highly critical 9.8 CVSS RCE in Windows IKE (CVE-2026-33824).
March Patch Tuesday visits 15 product families Microsoft's March Patch Tuesday addressed 84 vulnerabilities across 15 product families, including 8 Critical and 76 Important flaws. While no zero-days were reported as actively exploited, two vulnerabilities have been publicly disclosed, and six are deemed highly likely to be exploited within 30 days. Organizations are advised to prioritize patching for critical Remote Code Execution and Elevation of Privilege vulnerabilities affecting Windows, Office, and Azure environments.