Security news

Latest security news

Wed, 12 Aug 2026

  1. Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day

    Lazarus malware used post-quantum key exchange to protect delivery of a Windows zero-day exploit

    Infosecurity MagazineWindows, Exchange
  2. Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

    Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned

    Infosecurity MagazineMicrosoft, Fortinet
  3. NIST Seeks Public Input on AI-Ready NVD Modernization

    The US National Institute for Standards and Technology wants to modernize its National Vulnerability Database to embrace AI-powered vulnerability research

    Infosecurity Magazine
  4. Microsoft Fixes 400 Flaws on August Patch Tuesday

    Microsoft has issued another massive batch of security updates with 400 fixed in the August Patch Tuesday

    Infosecurity MagazineMicrosoft

Tue, 11 Aug 2026

  1. Microsoft Plugs Nearly 400 Security Holes

    Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

    Krebs on SecurityMicrosoft, Windows
  2. Patch Tuesday - August 2026

    Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month. SharePoint: critical RCE chain by Rapid7 Today sees the publication of CVE-2026-63520 , a high-severity remote code execution in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft; this vulnerability is the second in a pair of exploits which, when chained together, comprise a critical unauthenticated remote code execution vulnerability in a v

    Rapid7 BlogMicrosoft, Windows, SharePoint
  3. Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

    Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation industries. We observed the threat actor distributing modified PDF viewers designed to execute malicious payloads embedded within specially

    Check Point Research

About this news

1,263
Stories
35
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets