Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

August 11, 2026 3 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Windows OS and Server environments
Incident: Active exploitation of a Windows kernel driver zero-day and discovery of multiple critical RCEs.
Impact: Attackers can achieve full system privileges (SYSTEM) or execute remote code without authentication.
Attacker: Lazarus Group
Analysis: The primary threat is CVE-2026-68820, a use-after-free vulnerability in the afd.sys driver allowing attackers to escalate privileges to SYSTEM. Additionally, several unauthenticated RCEs in DNS and QUIC protocols present a severe risk of remote compromise. The ‘wormable’ nature of the DNS flaw specifically increases the potential for rapid, automated proliferation across networks.
Recommendations: Immediately apply August security updates, prioritizing CVE-2026-68820.; Audit and patch exposed Windows DNS, WDS, and QUIC services.; Verify that on-premises SharePoint farms have both the July and August updates installed.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Latest Developments

Update — 2026-08-11 21:43 UTC

Active exploitation of a privilege escalation zero-day (CVE-2026-68820) alongside 397 other patched vulnerabilities. Successful exploitation allows attackers to elevate low-privilege access to full system control. The latest update cycle reveals a massive spike in vulnerability discovery, which Microsoft attributes to the use of artificial intelligence. Of primary concern is CVE-2026-68820, a privilege escalation flaw in the afd.sys driver that is currently being exploited in the wild. With 42 critical flaws identified, attackers have multiple paths to gain remote control or full system authority.

Corroborating source: krebsonsecurity.com

Update — 2026-08-12 18:18 UTC

Exploitation of a Windows zero-day via social engineering to deploy backdoors. Full system compromise and potential theft of sensitive defense and aerospace data. The Lazarus Group is utilizing CVE-2026-68820 to escalate privileges to SYSTEM level after gaining initial access via fake job offers on LinkedIn. The campaign employs a dual-track infection strategy using both DLL side-loading and trojanized PDF readers to deploy the Troy and ForestTiger backdoors. This evolution of Operation Dream Job demonstrates high persistence and a continued focus on strategic intelligence gathering.

Corroborating source: thehackernews.com

Update — 2026-08-17 15:54 UTC

A series of diverse attacks including ransomware, large-scale data breaches, and AI-powered espionage campaigns. Exposure of millions of medical records, compromise of defense technical data, and breach of government infrastructure. Threat actors are increasingly leveraging autonomous AI agents for reconnaissance and malware development, specifically linked to Chinese and North Korean operations. Simultaneously, traditional social engineering continues to compromise corporate environments, while vulnerabilities in AI reasoning blocks expose sensitive API keys and credentials. The current landscape demonstrates a shift toward AI-augmented cyberespionage alongside critical system exploits.

Corroborating source: research.checkpoint.com

Leave a Reply

Your email address will not be published. Required fields are marked *