PLAYSTATION 5 Forza Horizon 6 Datamine Suggests Physical Disc and PlayStation 5 Release NINTENDO SWITCH Arcade Archives Fighting Golf launches October 8 for $9.99 on PS5 and Xbox Series AMD HP ZBook Ultra G3a workstation launches in Japan with up to 128 GB RAM and 120 Hz display INTEL Lenovo IdeaPad Slim 3i 15 launches in North America with 120 Hz display and $1,049 price tag STEAM Deadlock Hits 236,000 Peak Players as Valve Adds Baba to City Never Sleeps Update GAMES Resident Evil Requiem DLC to focus on Spencer, with Veronica and RE1 remakes in development GAMES Garry’s Mod creator admits s&box launch was a failure that burned bridges GAMES Canceled Perfect Dark Sequel Gameplay Footage Emerges Online INTEL Asus launches fanless NUC 14 Essential with 0.74L chassis and 6W Intel processors ANDROID Ratchet & Clank: Ranger Rumble goes global on Android and iOS LINUX Unofficial Metroid Prime Port Runs Natively on Android and PC Without Emulator NINTENDO New Denuvo Cracker IskoV Claims First Victory Over EA Sports FC 27 DRM GAMES Datamined Discord files hint at GTA 6 PC release speculation ahead of November console launch GAMES Resident Evil Requiem DLC Expected Next Year After Writer Leak

Microsoft Patches Critical Windows Zero-Day Exploited by Lazarus Group

Simon Ellis 2 min read

Microsoft released the August 2026 Patch Tuesday update, fixing 421 CVEs including a critical zero- day in afd.sys actively exploited by the Lazarus Group.

Microsoft Windows
SOFTWARE AND UPDATES

Microsoft released the August 2026 Patch Tuesday update to close 421 security vulnerabilities across Windows systems. This release matters because it addresses critical flaws that attackers are actively exploiting right now. Users who delay installation leave their devices exposed to immediate threats from known attack vectors.

August update closes 421 vulnerabilities including active North Korean attacks

The update targets core Windows components and related server software. It fixes a critical zero-day in the Windows Ancillary Function Driver for WinSock (afd.sys). Microsoft also patched an elevation-of-privilege bug in the Windows User Profile Service. SharePoint Server received a fix for a remote code execution vulnerability.

Check Point Research identified that the afd.sys flaw, CVE-2026-68820, is being actively exploited by North Korea's Lazarus Group. The group is using this vulnerability in its 'Operation Dream Job' campaign to target specific users. Rapid7 disclosed the SharePoint Server flaw, CVE-2026-63520, as part of a Pwn2Own Berlin exploit chain. Researcher Nightmare Eclipse also released a proof-of-concept for the Windows User Profile Service bug, CVE-2026-62832.

More than 40 of the 421 fixed vulnerabilities are rated critical by Microsoft. These critical flaws allow attackers to gain high-level access or execute code remotely. The patch includes fixes for various other issues not rated as critical but still posing risks. CISA listed this update as part of their recommended security actions for federal systems.

We looked at the last Windows update while tracking these security themes. That previous patch focused on balance and stability improvements for hardware integration. This month's release prioritizes active threat mitigation over feature additions. Organizations should verify that their SharePoint and Windows endpoints are patched immediately.

Source: NotebookCheck