Security news
Latest security news
Wed, 12 Aug 2026
- Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day
Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit
Infosecurity MagazineWindows, Exchange - Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure
Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned
Infosecurity MagazineMicrosoft, Fortinet - NIST Seeks Public Input on AI-Ready NVD Modernization
The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research
Infosecurity Magazine - RoguePlanet Vulnerability Still ExploitableHacker News
- Microsoft Fixes 400 Flaws on August Patch Tuesday
Microsoft has issued another massive batch of security updates with 400 fixed in the August Patch Tuesday
Infosecurity MagazineMicrosoft
Tue, 11 Aug 2026
- Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
Krebs on SecurityMicrosoft, Windows - Patch Tuesday - August 2026
Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month. SharePoint: critical RCE chain by Rapid7 Today sees the publication of CVE-2026-63520 , a high-severity remote code execution in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft; this vulnerability is the second in a pair of exploits which, when chained together, comprise a critical unauthenticated remote code execution vulnerability in a v
Rapid7 BlogMicrosoft, Windows, SharePoint - Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysHacker NewsMicrosoft
- Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. We observed the threat actor distributing modified PDF viewers designed to execute malicious payloads embedded within specially
Check Point Research
About this news
- 1,263
- Stories
- 35
- Added in the last 24 hours
- 16
- Critical in the last 7 days
- 4
- Reported by several outlets