ELSEIF
Your brief EB
333 stories from 95 feeds 232 clusters Refreshed 13 minutes ago next pull 06:06

TECH Signal 336

Microsoft patches 421 bugs, including zero-day already exploited by Lazarus

Microsoft's August Patch Tuesday addresses 421 CVEs, including a Windows zero-day that Lazarus Group exploited in attacks on defense organizations.

WHY IT MATTERS

With 421 fixes, this is a heavy patch cycle, and the fact that one bug was already exploited as a zero-day means patching that flaw should be top priority. The attack used a kernel-mode rootkit and a new backdoor, indicating a sophisticated threat actor.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Microsoft addressed 421 CVEs in its August Patch Tuesday, about 200 fewer than last month.

02

CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock, was exploited as a zero-day by Lazarus Group.

03

The attacks were part of Operation Dream Job, targeting defense sector in Europe and India with fake job offers and trojanized PDF viewer.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
www.theregister.com - Articles 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one Open ↗