SecurityWeek · 2026-08-12T00:00:00.000Z
A critical vulnerability in Microsoft SharePoint, previously patched in July, is now being actively exploited in real-world attacks. This exploitation began shortly after a proof-of-concept (PoC) exploit was publicly released, despite prior warnings from CISA about potential misuse. The active exploitation poses a significant security risk to organizations using vulnerable SharePoint versions.
Security Affairs · 2026-08-12T00:00:00.000Z
Microsoft has released its August 2026 Patch Tuesday updates, resolving 398 vulnerabilities across its products. Key fixes include a critical, actively exploited zero-day flaw (CVE-2026-68820) in Windows WinSock, allowing privilege escalation, and a wormable DNS vulnerability (CVE-2026-62878) enabling remote code execution without user interaction. These updates are crucial for protecting systems against significant security threats.
Qualys Blog · 2026-08-12T00:00:00.000Z
Microsoft's August 2026 Patch Tuesday addresses 421 vulnerabilities across its products and services, including one zero-day (CVE-2026-68820) actively exploited by North Korean attackers to deploy a kernel-mode rootkit. The updates also fix three publicly disclosed vulnerabilities and numerous high-severity issues, emphasizing the critical need for timely patching to mitigate risks like remote code execution and privilege escalation.
Cybercrime Magazine / The Hacker News · 2026-08-12T00:00:00.000Z
A Polish combined heat and power plant experienced a cyberattack, with hackers gaining control of its systems via the local grid operator's private cellular network. The attackers successfully shut down a steam turbine and the process-water treatment system. This incident highlights critical vulnerabilities in industrial control systems connected to private networks, posing significant infrastructure security concerns.