Výsledky hledání

výrobce: Microsoft× v celém archivu zrušit filtry

1035 karet z 1072 položek · strana 8 z 18 CZ · EN/orig

4

New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive…

CVSS 7.0 Microsoft veřejná správa finance zdravotnictví výroba a průmysl US

tg: rozbor tp: ransomware tp: AI tp: špionáž tp: průmyslové systémy

· Rapid7 · New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability CVE-2026-65400 Apple macOS Improper Authentication Vulnerability These types of vulnerabilities are a frequent attack vector…

KEV ✓ · ransomware EPSS 0.73 CVE-2026-33824 CVE-2026-55040 CVE-2026-59310 CVE-2026-65400 Microsoft Broadcom Apple veřejná správa US

· CISA Advisories · CISA Adds Four Known Exploited Vulnerabilities to Catalog

SPOJENO PŘES CVE Microsoft SharePoint Weak Authentication Vulnerability (CVE-2026-55040)

CISA added CVE-2026-55040 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft SharePoint. Remediation due date: 2026-08-21.

KEV ✓ EPSS 0.51 CVE-2026-55040 Microsoft US

· CISA KEV · Microsoft SharePoint Weak Authentication Vulnerability (CVE-2026-55040) · Rapid7 · Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) · Microsoft Security · CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability

7

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts.Key takeawaysStorm-0501 demonstrates that cloud-first ransomware groups have shifted from simple endpoint encryption to the total hijacking of cloud tenants.Storm-0501 systematically…

Microsoft US

tg: rozbor tg: propagace tp: ransomware tp: identita

· Tenable Research · Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

SPOJENO PŘES CVE Microsoft Edge security advisory (AV26-822)

Serial Number: AV26-822Date: August 17, 2026 As of August 14, 2026, Microsoft is affected by a vulnerability in the following product: Microsoft Edge (Chromium-based) Prior to 151.0.4129.86 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Microsoft Edge Stable Channel Release Notes Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability CVE-2026-72970 (en anglais seulement)

EPSS 0.01 CVE-2026-72970 Microsoft CA US

· Cyber Centre Kanada · Microsoft Edge security advisory (AV26-822) · Microsoft Security · CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

17th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were encrypted but stated that no data theft was detected during the incident. MyDr, Poland’s primary…

KEV ✓ EPSS 0.25 CVSS 9.8 CVE-2026-53413 CVE-2026-65400 CVE-2026-68820 CVE-2026-71362 Microsoft Apple Adobe Zoom veřejná správa zdravotnictví obrana energetika IL

· Check Point Research · 17th August – Threat Intelligence Report

2608-patch-tuesday

<p>423 CVEs, no Edge patches, and a small shift in CWE findings</p>Categories: Threat ResearchTags: Patch Tuesday, MICROSOFT PATCH TUESDAY

Microsoft GB

· Sophos Threat Research · 2608-patch-tuesday

Multiples vulnérabilités dans Microsoft Edge (17 août 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un problème de sécurité non spécifié par l'éditeur.

EPSS 0.01 CVE-2026-19556 CVE-2026-19557 CVE-2026-19558 CVE-2026-19559 CVE-2026-19560 CVE-2026-72970 Microsoft FR

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft Edge (17 août 2026)

1

Riasztás Microsoft szoftverek 2026 augusztusában javított sérülékenységeiről

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Microsoft szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán azok súlyossága, a szoftverek széleskörű elterjedtsége, valamint az egyes biztonsági hibákat érintő aktív kihasználások miatt. A Microsoft tárgyhavi biztonsági csomagjában összesen 421 különböző biztonsági hibát javított, köztük 3 db nulladik napi (zero-day) sebezhetőséget is amelyet a Microsoft […]

Microsoft HU

· NKI Maďarsko · Riasztás Microsoft szoftverek 2026 augusztusában javított sérülékenységeiről

1

Riasztás a Lazarus „Operation Dream Job” kampányról és a CVE‑2026‑68820 Windows sérülékenységről

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Windows kernelt érintő, észak-koreai kötődésű Lazarus csoport által végrehajtott célzott kampánnyal kapcsolatban, amelyben trójai PDF nézők, fejlett in‑memory moduláris kártevők és több zero‑day/exploittal támogatott támadási lánc kerül alkalmazásra. A kampány részeként a támadók a Microsoft Windows AFD.sys illesztőprogram egy korábban nem publikált (0-day) use‑after‑free típusú […]

Microsoft veřejná správa HU

· NKI Maďarsko · Riasztás a Lazarus „Operation Dream Job” kampányról és a CVE‑2026‑68820 Windows sérülékenységről

8

Patch Tuesday: Update now to fix 421 flaws, including three zero-days

Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges. The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely to attract attacker interest: a publicly disclosed Windows privilege escalation flaw with a proof-of…

EPSS 0.03 CVSS 9.8 CVE-2026-62832 CVE-2026-62893 Microsoft školství veřejná správa US

· Malwarebytes Labs · Patch Tuesday: Update now to fix 421 flaws, including three zero-days

Multiples vulnérabilités dans Microsoft Azure (12 août 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

EPSS 0.01 CVE-2026-47299 CVE-2026-57104 CVE-2026-65806 CVE-2026-6726 CVE-2026-6727 CVE-2026-70340 Microsoft finance veřejná správa FR

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft Azure (12 août 2026)

Multiples vulnérabilités dans Microsoft .Net (12 août 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

EPSS 0.01 CVE-2026-58641 CVE-2026-62871 CVE-2026-62872 CVE-2026-62886 CVE-2026-62897 CVE-2026-62898 CVE-2026-62899 CVE-2026-62900 CVE-2026-62901 CVE-2026-62902 CVE-2026-62909 CVE-2026-65810 CVE-2026-70354 Microsoft FR

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft .Net (12 août 2026)

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical." Microsoft notes that 1 of the vulnerabilities disclosed this month have been exploited in the wild CVE-2026-68820 is an elevation of privilege vulnerability affecting Windows Ancillary Function Driver for WinSock. A Use After Free vulnerability could allow an authorized attacker to elevate privileges locally. This…

Microsoft US

· Cisco Talos · Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

39

Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review

The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthening enterprise security. Microsoft Patch Tuesday for August 2026 This month’s release addresses 421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities. In this month’s updates, Microsoft…

Microsoft Adobe US

· Qualys · Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review

Patch Tuesday - August 2026

Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday, including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the…

KEV ✓ EPSS 0.51 CVSS 5.5 CVE-2026-50656 CVE-2026-55040 CVE-2026-62832 CVE-2026-63520 CVE-2026-6726 CVE-2026-6727 CVE-2026-68820 CVE-2026-72971 Microsoft US

· Rapid7 · Patch Tuesday - August 2026

The August 2026 Security Update Review

I’ve successfully survived Hacker Summer Camp, and I have returned with a new outlook on patch density. When even Linus Torvalds says that huge updates are the “new normal”, it’s time to readjust what we consider a true bug apocalypse. This month’s release is thankfully smaller than last months, but still huge by historical standards. Take a break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full…

Adobe Microsoft US

· ZDI Blog · The August 2026 Security Update Review

Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)

This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs. A few vulnerabilities worth mentioning: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820) This Important-severity elevation of privilege vulnerability is…

KEV ✓ EPSS 0.06 CVSS 9.8 CVE-2026-62815 CVE-2026-62832 CVE-2026-62878 CVE-2026-68820 CVE-2026-72971 Microsoft US

· SANS Internet Storm Ctr. · Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)

Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

Key Points Check Point Research is tracking a long‑running campaign called Operation Dream Job, targeting organizations worldwide, with a particular focus on the defense sector. The campaign is affiliated to DPRK-linked Lazarus group and its latest wave focuses on the defense sector in Europe and India. In the latest variant of the Operation Dream Job campaign, the threat actor distributed SecurityPDF, a modified PDF viewer designed to open attacker-crafted PDF documents and execute a new…

KEV ✓ EPSS 0.99 CVE-2025-49113 CVE-2026-68820 Microsoft obrana IL

· Check Point Research · Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack

CVE-2026-6727 MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability

[CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) is an Information Disclosure vulnerability in the TPM 2.0 reference implementation involving an RSA OAEP timing side channel. MITRE assigned this CVE on behalf of the Trusted Computing Group. This document incorporates updates to Microsoft Windows that address this vulnerability. Please see [CVE-2026-6727](https://www.cve.org/CVERecord?id=CVE-2026-6727) for more information.

EPSS 0.00 CVE-2026-6727 Microsoft US

· Microsoft Security · CVE-2026-6727 MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability

SPOJENO PŘES CVE CVE-2026-65773 Windows Kernel Elevation of Privilege Vulnerability

Improper access control in Windows Kernel allows an authorized attacker to elevate privileges locally.

EPSS 0.00 CVSS 7.8 CVE-2026-65773 Microsoft US

· Microsoft Security · CVE-2026-65773 Windows Kernel Elevation of Privilege Vulnerability · Zero Day Initiative · ZDI-26-539: (Pwn2Own) Microsoft Windows ipt.sys Incorrect Permission Assignment Local Privilege Escalation Vulnerability