ANDROID Vivo V70 Lite 4G Adds 8,100mAh Battery, Drops 5G for Unisoc Chip STEAM Phantom Blade Zero Pre-Orders Hit 300K, Chasing Black Myth: Wukong INTEL Asus CX9406 Googlebook Leak: Panther Lake CPU, 16GB RAM, $1,383 Price GAMES GTA 6 Leaked Footage Shows Driving and Strip Club Scenes CONSOLES The Duskbloods Switch 2 Input Lag Hits 200ms in Network Test PC HARDWARE Philips Evnia 27-inch 260Hz Monitor Launches for $190 GAMES GTA 6 Leaks Hit Rockstar Morale, Netflix Unfazed by Early Footage AMD AMD Desktop CPU Share Hits 34.9% in Q2 2026 as Intel Loses Ground GAMES WWE 2K26 Patch 1.15 Adds Finn Balor Theme and Fixes Match Bugs NVIDIA Modern Warfare 4 Beta Nerfs Frangible Rounds and Footsteps GAMES Modern Warfare 4 Beta Patch Tweaks TTK and Footstep Audio SOFTWARE AND UPDATES Twitch Faces Class Action Lawsuit Over Unlicensed AI Training INTEL Lenovo ThinkPad L14 Gen 7 Launches with Wi-Fi 7 and Core Ultra 3 for $1,109 STEAM Settler’s Domain Launches on Steam With Native ARM Support

Microsoft Patches Critical Windows Zero-Day Exploited by Lazarus Group

Simon Ellis 0 comments 2 min read

Microsoft released the August 2026 Patch Tuesday update, fixing 421 CVEs including a critical zero- day in afd.sys actively exploited by the Lazarus Group.

Microsoft Windows
SOFTWARE AND UPDATES

Microsoft released the August 2026 Patch Tuesday update to close 421 security vulnerabilities across Windows systems. This release matters because it addresses critical flaws that attackers are actively exploiting right now. Users who delay installation leave their devices exposed to immediate threats from known attack vectors.

August update closes 421 vulnerabilities including active North Korean attacks

The update targets core Windows components and related server software. It fixes a critical zero-day in the Windows Ancillary Function Driver for WinSock (afd.sys). Microsoft also patched an elevation-of-privilege bug in the Windows User Profile Service. SharePoint Server received a fix for a remote code execution vulnerability.

Check Point Research identified that the afd.sys flaw, CVE-2026-68820, is being actively exploited by North Korea's Lazarus Group. The group is using this vulnerability in its 'Operation Dream Job' campaign to target specific users. Rapid7 disclosed the SharePoint Server flaw, CVE-2026-63520, as part of a Pwn2Own Berlin exploit chain. Researcher Nightmare Eclipse also released a proof-of-concept for the Windows User Profile Service bug, CVE-2026-62832.

More than 40 of the 421 fixed vulnerabilities are rated critical by Microsoft. These critical flaws allow attackers to gain high-level access or execute code remotely. The patch includes fixes for various other issues not rated as critical but still posing risks. CISA listed this update as part of their recommended security actions for federal systems.

We looked at the last Windows update while tracking these security themes. That previous patch focused on balance and stability improvements for hardware integration. This month's release prioritizes active threat mitigation over feature additions. Organizations should verify that their SharePoint and Windows endpoints are patched immediately.

Source: NotebookCheck

Discussion

0 comments

Leave a comment