{"id":17708,"date":"2026-08-13T16:55:50","date_gmt":"2026-08-13T16:55:50","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=17708"},"modified":"2026-08-13T16:55:50","modified_gmt":"2026-08-13T16:55:50","slug":"microsoft-plugs-practically-400-safety-holes-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=17708","title":{"rendered":"Microsoft Plugs Practically 400 Safety Holes \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><strong>Microsoft<\/strong> at the moment launched updates to treatment not less than 398 safety vulnerabilities in its <strong>Home windows<\/strong> working programs and supported software program, together with one weak spot that&#8217;s already being actively exploited and two others that have been publicly detailed previous to at the moment.<\/p>\n<div id=\"attachment_74109\" style=\"width: 758px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-74109\" decoding=\"async\" class=\" wp-image-74109\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/workingonpc.png\" alt=\"\" width=\"748\" height=\"531\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/workingonpc.png 649w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/08\/workingonpc-100x70.png 100w\" sizes=\"auto, (max-width: 748px) 100vw, 748px\"\/><\/p>\n<p id=\"caption-attachment-74109\" class=\"wp-caption-text\">Picture: Shutterstock, Mallika Dwelling Studio.<\/p>\n<\/div>\n<p>August\u2019s overstuffed bundle of patch pleasure from Microsoft didn&#8217;t eclipse its recording breaking launch of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2026\/07\/microsoft-patches-a-record-570-security-flaws\/\" target=\"_blank\" rel=\"noopener\">greater than 570 safety updates final month<\/a>, however it&#8217;s double June\u2019s then-record batch of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2026\/06\/a-record-breaking-patch-tuesday-for-june-2026\/#more-73788\" target=\"_blank\" rel=\"noopener\">almost 200 fixes<\/a>. Microsoft has attributed the current patch deluge to vulnerability discoveries aided by synthetic intelligence, and specialists roundly agree that Home windows customers ought to get used to the thought of Patch Tuesdays (the second Tuesday of every month) overlaying a whole bunch of newly found safety flaws.<\/p>\n<p>Totally 42 of the 398 flaws that Microsoft patched at the moment earned Redmond\u2019s most-dire \u201cessential\u201d score, which means they&#8217;re extreme sufficient that malware or malcontents might exploit them to realize distant management over a Home windows pc with little to no assist from the consumer.<\/p>\n<p>The only real identified \u201czero day\u201d bug fastened by Microsoft this month is <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-68820\" target=\"_blank\" rel=\"noopener\">CVE-2026-68820<\/a>, a privilege escalation weak spot in a core Home windows element known as <strong>afd.sys<\/strong>, which the safety agency <strong>Automox<\/strong> describes as \u201cthe driving force behind Home windows socket connections on successfully each endpoint.\u201d<\/p>\n<p>\u201cThis isn\u2019t a front-door bug,\u201d Automox\u2019s <strong>Landon Miles<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.automox.com\/blog\/patch-fix-tuesday-august-2026\" target=\"_blank\" rel=\"noopener\">wrote<\/a> in a Patch Tuesday weblog put up. \u201cIt\u2019s step two in a series: an attacker phishes their approach right into a low-privilege foothold, then makes use of the driving force flaw to take the field. The 7.0 rating displays the excessive assault complexity, as a result of race circumstances are fiddly. The exploit must be thrown again and again till the timing lands. Somebody is clearly touchdown it anyway.\u201d<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-62832\" target=\"_blank\" rel=\"noopener\">CVE-2026-62832<\/a> is one other privilege escalation flaw that Microsoft has labeled more likely to be exploited; this flaw, within the Home windows Consumer Profile Service, could also be associated to the current <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.theregister.com\/security\/2026\/07\/15\/microsofts-serial-tormentor-drops-legacyhive-0-day\/5271723\" target=\"_blank\" rel=\"noopener\">\u201cLegacyHive\u201d public disclosure<\/a> from the prolific bug hunter often known as <strong>Nightmare Eclipse<\/strong>. The opposite publicly disclosed flaw is <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-US\/advisory\/CVE-2026-72971\" target=\"_blank\" rel=\"noopener\">CVE-2026-72971<\/a>, a low-impact native tampering vulnerability that Microsoft reckons is unlikely to be exploited.<span id=\"more-74106\"\/><\/p>\n<p>Different main software program makers are likewise growing their patch volumes and cadence because of AI, together with <strong>Adobe<\/strong> which final month moved to twice-monthly safety bulletins revealed on the 2nd and 4th Tuesday of every month. <strong>Cisco<\/strong>, <strong>Google<\/strong>, <strong>Mozilla<\/strong> and <strong>Oracle<\/strong> are also transport updates much more steadily and abundantly.<\/p>\n<p>By all accounts, AI is sort of good at discovering safety holes in software program. However for now not less than, patching the ensuing bugpocalypse stays a closely human-centric endeavor, and the jury continues to be out on whether or not AI applied sciences will turn into nearly as good at fixing vulnerabilities as they&#8217;re at discovering and exploiting them. This is a vital query when one considers that these identical AI applied sciences are also suggesting fixes for the vulnerabilities they discover.<\/p>\n<p>Researchers at <strong>1Password<\/strong> not too long ago <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/1password.com\/blog\/why-ai-generated-patches-still-require-human-review\" target=\"_blank\" rel=\"noopener\">examined<\/a> what occurs when totally different massive language fashions (LLMs) generate vulnerability patches for newly disclosed, advanced vulnerabilities. They discovered the LLMs produced patches that failed to repair the flaw or added a brand new weak spot within the course of (or each) greater than half the time.<\/p>\n<p><strong>Ed Skoudis<\/strong>, president of the <strong>SANS Expertise Institute<\/strong>, mentioned his crew has seen wonderful outcomes utilizing AI to generate patches, supplied there are people within the loop to check the advised fixes and push for iterative enhancements.<\/p>\n<p>\u201cAI is quickly turning into astonishingly good at discovering vulnerabilities, however this analysis reveals that fixing them is a really totally different downside,\u201d Skoudis wrote in a SANS publication at the moment. \u201cDon\u2019t count on one-shot AI patching to work reliably. As an alternative, iterate, take a look at, problem, enhance, and confirm. AI could be a unprecedented patching associate, however at the moment it nonetheless wants a talented human on the keyboard.\u201d<\/p>\n<p><strong>Tyler Reguly<\/strong> at <strong>Fortra<\/strong> says whereas stories of Microsoft patching a whole bunch of vulnerabilities in a single go have prompted some organizations to attempt to patch quicker, it\u2019s essential to keep in mind that solely one of many virtually 400 bugs addressed at the moment is understood to be actively exploited. Reguly advised safety leaders examine in with their groups to see how they\u2019re dealing with the growing workloads, which frequently contain testing fixes earlier than deploying them in manufacturing environments.<\/p>\n<p>\u201cShould you\u2019re a chief safety officer discuss to your groups about how they&#8217;re shifting or modifying their workflows to higher accommodate the patching shift that we\u2019re seeing and help them throughout varied organizational items by enabling the adjustments they need to see made,\u201d Reguly mentioned. \u201cThere\u2019s no have to rush these updates, it doesn&#8217;t matter what varied distributors and organizations attempt to inform you. It&#8217;s essential to just remember to are rolling out secure updates that won&#8217;t negatively affect your programs.\u201d<\/p>\n<p>Talking of the people behind the keyboards, don\u2019t neglect to backup your system and\/or information earlier than making use of this month\u2019s monster patch load. The day after every month\u2019s Patch Tuesday is usually derisively known as Reboot Wednesday, however it typically doesn\u2019t harm to attend a number of days to use these large replace bundles as a result of it generally takes a few days for the occasional misbehaving patch to get ironed out correctly by Microsoft.<\/p>\n<p>For a clickable, per-patch breakdown by severity and urgency, try <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/isc.sans.edu\/diary\/Microsoft%20Patch%20Tuesday%20August%202026\/33236\" target=\"_blank\" rel=\"noopener\">this roundup<\/a> from the SANS Web Storm Middle.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Microsoft at the moment launched updates to treatment not less than 398 safety vulnerabilities in its Home windows working programs and supported software program, together with one weak spot that&#8217;s already being actively exploited and two others that have been publicly detailed previous to at the moment. Picture: Shutterstock, Mallika Dwelling Studio. August\u2019s overstuffed bundle [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":17710,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[10152,262,618,7386,211],"class_list":["post-17708","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-holes","tag-krebs","tag-microsoft","tag-plugs","tag-security"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=17708"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17708\/revisions"}],"predecessor-version":[{"id":17709,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/17708\/revisions\/17709"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/17710"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=17708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=17708"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=17708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-08-13 18:20:36 UTC -->