17th August – Threat Intelligence Report
Microsoft released its August 2026 patch updates to address 421 vulnerabilities, critically including CVE-2026-68820, a Windows Ancillary Function Driver for WinSock zero-day that is currently being exploited by Lazarus-linked actors to achieve SYSTEM privileges via local privilege escalation. Simultaneously, Adobe deployed an urgent fix for CVE-2026-71362 in Adobe Commerce and Magento Open Source, reporting immediate attacks shortly after public disclosure that allow unauthorized session switching and account takeover. Additionally, Zoom issued patches for three critical flaws, such as CVE-2026-53413, which permit remote code execution without user interaction through meeting annotations.