Microsoft August 2026 Patch Tuesday security updates (3 zero-days)
Security Patch Release
Summary
Hide ▲
Show ▼
Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active exploitation and can let a local attacker escalate to SYSTEM. Check Point Research says Lazarus used the zero-day in its Operation Dream Job campaign against defense and aerospace companies in Europe and India. The latest analysis says the malware negotiated its command channel with a post-quantum key exchange before pulling down the exploit, then loaded FudModule v3.1 through MISTPEN with layered encryption. The same infrastructure also used RelayShell, impersonation sites for Enveil, and a backdoor called Troy.
Related Happenings
Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India
Campaign
H score22
First: 12.08.2026 16:35
Last: 12.08.2026 16:35
Sources 1
How related:
Malware used by North Korea's Lazarus group negotiated its command channel using a post-quantum key exchange before pulling down a Windows zero-day exploit, in a campaign against defense and aerospace companies across Europe and India.
About this happening:
Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India,...
Lazarus Operation Dream Job campaign against defense and aerospace firms in Europe and India
CampaignHow related: Malware used by North Korea's Lazarus group negotiated its command channel using a post-quantum key exchange before pulling down a Windows zero-day exploit, in a campaign against defense and aerospace companies across Europe and India.
About this happening: Lazarus Group continued Operation Dream Job with a Windows zero-day campaign that targeted defense, aerospace, and aviation organizations in Europe and India,...
Latest development: 12.08.2026 18:38
Lazarus broadened the Operation Dream Job campaign against defense, aerospace, and aviation organizations in Europe and India by using fraudulent recruitment offers, with successful targeting also observed in Western Europe, including France and Germany, and activity extending into South America, including Brazil. Check Point also tied the latest wave to the Troy backdoor, a FudModule variant with a CVE-2026-68820 exploit, and compromised Roundcube instances used to hide malicious communications and deploy the RelayShell web shell.
Microsoft security patch release for CVE-2026-68820
Security Patch Release
H score28
First: 12.08.2026 00:28
Last: 12.08.2026 00:28
Sources 1
About this happening:
Microsoft released August 2026 Patch Tuesday updates for Windows operating systems and supported software, fixing at least 398 vulnerabilities. The bundle includes...
Microsoft security patch release for CVE-2026-68820
Security Patch ReleaseAbout this happening: Microsoft released August 2026 Patch Tuesday updates for Windows operating systems and supported software, fixing at least 398 vulnerabilities. The bundle includes...
Windows 10 KB5120249 cumulative update (August 2026 Patch Tuesday)
Security Patch Release
H score26
First: 11.08.2026 21:26
Last: 11.08.2026 21:26
Sources 1
About this happening:
Microsoft released Windows 10 KB5120249 for versions 22H2 and 21H2, making it a mandatory Patch Tuesday update for supported systems. The release fixes security...
Windows 10 KB5120249 cumulative update (August 2026 Patch Tuesday)
Security Patch ReleaseAbout this happening: Microsoft released Windows 10 KB5120249 for versions 22H2 and 21H2, making it a mandatory Patch Tuesday update for supported systems. The release fixes security...
Microsoft Security launches Project Perception, MAI-Cyber-1-Flash, FORGE Lab, and EXTRA
Security Tool/Service
H score11
First: 28.07.2026 15:45
Last: 28.07.2026 15:45
Sources 1
About this happening:
Microsoft Security launched Project Perception, an agentic security system that uses Red, Blue and Green agents to identify vulnerabilities, triage risk, and automate reme...
Microsoft Security launches Project Perception, MAI-Cyber-1-Flash, FORGE Lab, and EXTRA
Security Tool/ServiceAbout this happening: Microsoft Security launched Project Perception, an agentic security system that uses Red, Blue and Green agents to identify vulnerabilities, triage risk, and automate reme...
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/Mitigation
H score56
First: 15.07.2026 17:07
Last: 15.07.2026 17:07
Sources 1
About this happening:
CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/MitigationAbout this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
Timeline
-
12.08.2026 16:35 1 articles · 13d ago
Lazarus uses post-quantum handshake to deliver FudModule v3.1 through CVE-2026-68820
Technical Analysis UpdateLazarus group malware used a post-quantum key exchange to negotiate its command channel, then pulled down a Windows zero-day exploit in an Operation Dream Job campaign against defense and aerospace companies in Europe and India. The chain ran through MISTPEN, an in-memory downloader that fetched FudModule v3.1, a kernel rootkit that disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger, blinds 94 ETW providers, and tampers with Smart App Control; the same infrastructure also used RelayShell and impersonation sites for Enveil to distribute Troy.
Show sources
- Lazarus Used Post-Quantum Key Exchange to Deliver Zero-Day — www.infosecurity-magazine.com — 12.08.2026 16:35
-
11.08.2026 21:08 3 articles · 13d ago
Microsoft releases August 2026 Patch Tuesday security updates for 400 flaws
Initial DisclosureMicrosoft released August 2026 Patch Tuesday security updates for 400 flaws, including CVE-2026-68820 in Windows Ancillary Function Driver for WinSock (AFD.sys), which can let a locally authenticated attacker gain SYSTEM privileges, plus two publicly disclosed zero-days in Windows User Profile Service (CVE-2026-62832) and Windows Container Isolation FS Filter Driver (unionfs.sys) (CVE-2026-72971). Check Point said Lazarus exploited CVE-2026-68820 to deploy a new version of FudModule, and Microsoft said the release also addresses 42 Critical vulnerabilities.
Show sources
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days — www.bleepingcomputer.com — 11.08.2026 21:08
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days — www.bleepingcomputer.com — 11.08.2026 21:08
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack — thehackernews.com — 11.08.2026 23:10