Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Microsoft's August 2026 Patch Tuesday addresses a record 398 CVEs, with 42 rated critical, 355 important, and one moderate. The update includes patches for a wide range of products, such as .NET, Azure services, Microsoft Office, Windows components, and third-party integrations like GitHub Copilot.
Microsoft released Windows 11 cumulative updates KB5121003 and KB5120240 for versions 25H2/24H2 and 23H2. These updates address security vulnerabilities, fix bugs, and add new features to enhance system performance and protection.
Check Point Research tracks Operation Dream Job, a Lazarus group campaign targeting defense sectors with zero-day exploits and modified PDF viewers. The attackers use CVE-2026-68820 and CVE-2025-49113 to deploy backdoors and relay nodes, with Microsoft patching the zero-day in August 2026.
The article discusses Chrome's multi-layered defenses against abusive push notifications. It highlights the growing problem of deceptive notifications and Chrome's efforts to mitigate them.
Researchers have uncovered an AI-assisted exploit chain targeting on-premises Microsoft SharePoint servers, combining an authentication bypass (CVE-2026-55040, CVSS 9.1) with a remote code execution flaw (CVE-2026-63520, CVSS 8.1) to achieve unauthenticated RCE. The bypass allows an attacker to impersonate any known user by SID or UPN, while the RCE flaw in Business Connectivity Services executes code as the SharePoint service account. The attack chain affects SharePoint Server 2016, 2019, and Subscription Edition, but not SharePoint Online.
DeadLock ransomware leverages decentralized infrastructure, including Polygon smart contracts and Session messaging, to enhance operational resilience.