Topic: microsoft patch tuesday
-
Microsoft's April 2026 Patch Tuesday fixes 167 flaws, 2 zero-days
Microsoft's April 2026 Patch Tuesday security update addresses 167 vulnerabilities across its software. Two of the flaws were actively exploited zero-day vulnerabilities, posing a critical threat before being fixed. System administrators and users are urged to promptly deploy the updates to prote...
Read More » -
Microsoft's Patch Tuesday: 421 bugs, North Korea exploits one
Microsoft patched 421 vulnerabilities in August, including the zero-day CVE-2026-68820 exploited by North Korea's Lazarus Group in early June, a Windows AFD.sys use-after-free flaw enabling SYSTEM-level code execution without user interaction. Lazarus used this zero-day in Operation Dream Job, a ...
Read More » -
Microsoft Patches Bug in Age of Empires II
Microsoft released its largest-ever batch of security patches, driven by the expanded use of AI in discovering vulnerabilities at an unprecedented scale. A critical remote code execution bug in the remastered Age of Empires II, tracked as CVE-2026-50663, could let attackers take full control of a...
Read More » -
Microsoft patches record number of security flaws, cites AI role
Microsoft issued its largest-ever batch of security patches, fixing 570 vulnerabilities, due to AI-powered vulnerability detection that has drastically increased discovered flaws. The update included at least two zero-day exploits, including a critical Windows Server privilege escalation bug and ...
Read More » -
Microsoft Fixes Record 570 Security Flaws in One Patch
Microsoft's July 2026 Patch Tuesday set a record by addressing 570 vulnerabilities, nearly tripling last month's total, largely due to AI-driven vulnerability discovery tools. The update patches nearly 60 critical flaws, three zero-day vulnerabilities (two actively exploited), and roughly 250 ele...
Read More » -
Microsoft patches zero-day flaw as Mirai botnets hit Wazuh servers
Microsoft patched 66 security flaws, including a zero-day exploit (CVE-2025-33053), while Mirai botnets targeted unpatched Wazuh servers via a critical RCE flaw (CVE-2025-24016). Threat modeling is undervalued despite its importance, as competing priorities like new tools often overshadow it in b...
Read More » -
Microsoft SharePoint Spoofing Attacks Affect 1,300+ Servers
Over 1,300 internet-exposed Microsoft SharePoint servers remain vulnerable to an actively exploited spoofing flaw (CVE-2026-32201), despite a patch being released in April's security updates. The vulnerability, stemming from improper input validation, allows for network spoofing attacks that can ...
Read More » -
CISA orders federal agencies to patch exploited BlueHammer flaw
CISA has mandated that U.S. federal agencies patch a Microsoft Defender privilege escalation vulnerability (CVE-2026-33825, dubbed "BlueHammer") within two weeks, by May 7, due to active exploitation in zero-day attacks that grant attackers SYSTEM-level permissions. The vulnerability was publicly...
Read More » -
Google’s AI helped fix more Chrome bugs in June than in the past two years
Google fixed 1,072 security bugs in Chrome last month, more than in the previous two years combined, using internal AI tools. Google’s engineering director says LLMs have automated vulnerability discovery, allowing the company to preemptively fix flaws at an industrial scale. Microsoft also patch...
Read More »