Exploited in the wild Windows Lazarus Group patch-tuesday Microsoft Defender Microsoft
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)
CVE Tools coverage
Microsoft released over 400 security fixes in its August 2026 update cycle, addressing active attacks on Windows via a use-after-free flaw identified as CVE-2026-68820">CVE-2026-68820. Check Point researchers confirmed that Lazarus Group actors are leveraging this bug to install kernel-mode rootkits as part of their 'Operation Dream Job' intrusion campaign.
The release also resolved several previously disclosed issues, including a User Profile Service privilege escalation (CVE-2026-62832">CVE-2026-62832) and two other flaws with public proof-of-concept exploits. Notably, researcher "Nightmare Eclipse" has published a "ShieldBreak" tool that reportedly circumvents recent protections for the Microsoft Defender vulnerability CVE-2026-50656.