Wednesday, September 16, 2026
No Result
View All Result
Future News 24
Advertisement
  • Home
  • AI Research
  • Platforms
  • Ethics
  • Developer AI
  • Industry
  • Data Science
  • Emerging Tech
  • Quantum
  • BioTech
  • Decentralized
  • Home
  • AI Research
  • Platforms
  • Ethics
  • Developer AI
  • Industry
  • Data Science
  • Emerging Tech
  • Quantum
  • BioTech
  • Decentralized
No Result
View All Result
Future News 24
No Result
View All Result
Home Data Science & MLOps

Microsoft Plugs Almost 400 Safety Holes – Krebs on Safety

Future News 24 by Future News 24
August 12, 2026
in Data Science & MLOps
0 0
0
Microsoft Plugs Almost 400 Safety Holes – Krebs on Safety
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


Microsoft immediately launched updates to treatment not less than 398 safety vulnerabilities in its Home windows working methods and supported software program, together with one weak point that’s already being actively exploited and two others that had been publicly detailed previous to immediately.

Microsoft Plugs Almost 400 Safety Holes – Krebs on Safety

Picture: Shutterstock, Mallika House Studio.

August’s overstuffed bundle of patch pleasure from Microsoft didn’t eclipse its recording breaking launch of greater than 570 safety updates final month, however it’s double June’s then-record batch of almost 200 fixes. Microsoft has attributed the current patch deluge to vulnerability discoveries aided by synthetic intelligence, and specialists roundly agree that Home windows customers ought to get used to the thought of Patch Tuesdays (the second Tuesday of every month) masking lots of of newly found safety flaws.

Absolutely 42 of the 398 flaws that Microsoft patched immediately earned Redmond’s most-dire “essential” score, which means they’re extreme sufficient that malware or malcontents might exploit them to achieve distant management over a Home windows laptop with little to no assist from the consumer.

The only real identified “zero day” bug mounted by Microsoft this month is CVE-2026-68820, a privilege escalation weak point in a core Home windows part known as afd.sys, which the safety agency Automox describes as “the driving force behind Home windows socket connections on successfully each endpoint.”

“This isn’t a front-door bug,” Automox’s Landon Miles wrote in a Patch Tuesday weblog publish. “It’s step two in a series: an attacker phishes their method right into a low-privilege foothold, then makes use of the driving force flaw to take the field. The 7.0 rating displays the excessive assault complexity, as a result of race situations are fiddly. The exploit must be thrown again and again till the timing lands. Somebody is clearly touchdown it anyway.”

CVE-2026-62832 is one other privilege escalation flaw that Microsoft has labeled prone to be exploited; this flaw, within the Home windows Consumer Profile Service, could also be associated to the current “LegacyHive” public disclosure from the prolific bug hunter often known as Nightmare Eclipse. The opposite publicly disclosed flaw is CVE-2026-72971, a low-impact native tampering vulnerability that Microsoft reckons is unlikely to be exploited.

Different main software program makers are likewise rising their patch volumes and cadence because of AI, together with Adobe which final month moved to twice-monthly safety bulletins printed on the 2nd and 4th Tuesday of every month. Cisco, Google, Mozilla and Oracle are also delivery updates way more continuously and abundantly.

By all accounts, AI is sort of good at discovering safety holes in software program. However for now not less than, patching the ensuing bugpocalypse stays a closely human-centric endeavor, and the jury continues to be out on whether or not AI applied sciences will turn into nearly as good at fixing vulnerabilities as they’re at discovering and exploiting them. This is a vital query when one considers that these identical AI applied sciences are also suggesting fixes for the vulnerabilities they discover.

Researchers at 1Password lately examined what occurs when completely different massive language fashions (LLMs) generate vulnerability patches for newly disclosed, complicated vulnerabilities. They discovered the LLMs produced patches that failed to repair the flaw or added a brand new weak point within the course of (or each) greater than half the time.

Ed Skoudis, president of the SANS Expertise Institute, mentioned his workforce has seen glorious outcomes utilizing AI to generate patches, offered there are people within the loop to check the advised fixes and push for iterative enhancements.

“AI is quickly turning into astonishingly good at discovering vulnerabilities, however this analysis reveals that fixing them is a really completely different downside,” Skoudis wrote in a SANS e-newsletter immediately. “Don’t anticipate one-shot AI patching to work reliably. As a substitute, iterate, take a look at, problem, enhance, and confirm. AI will be a unprecedented patching accomplice, however immediately it nonetheless wants a talented human on the keyboard.”

Tyler Reguly at Fortra says whereas stories of Microsoft patching lots of of vulnerabilities in a single go have prompted some organizations to attempt to patch quicker, it’s essential to remember that solely one of many nearly 400 bugs addressed immediately is thought to be actively exploited. Reguly advised safety leaders examine in with their groups to see how they’re dealing with the rising workloads, which frequently contain testing fixes earlier than deploying them in manufacturing environments.

“For those who’re a chief safety officer speak to your groups about how they’re shifting or modifying their workflows to higher accommodate the patching shift that we’re seeing and assist them throughout numerous organizational items by enabling the modifications they need to see made,” Reguly mentioned. “There’s no have to rush these updates, it doesn’t matter what numerous distributors and organizations attempt to inform you. You must just remember to are rolling out secure updates that won’t negatively impression your methods.”

Talking of the people behind the keyboards, don’t neglect to backup your system and/or knowledge earlier than making use of this month’s monster patch load. The day after every month’s Patch Tuesday is typically derisively known as Reboot Wednesday, nevertheless it typically doesn’t harm to attend just a few days to use these enormous replace bundles as a result of it typically takes a few days for the occasional misbehaving patch to get ironed out correctly by Microsoft.

For a clickable, per-patch breakdown by severity and urgency, take a look at this roundup from the SANS Web Storm Middle.



Source link

Tags: holesKrebsMicrosoftPlugsSecurity
Previous Post

NVIDIA JetPack 7.2.1 Provides Agentic Video Expertise and T3000 Emulation

Next Post

Parasite-Particular Protein Helps Toxoplasma Adapt to Crowded Circumstances

Next Post
Parasite-Particular Protein Helps Toxoplasma Adapt to Crowded Circumstances

Parasite-Particular Protein Helps Toxoplasma Adapt to Crowded Circumstances

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Fetching latest news…
FUTURENEWS24
Live Feed
All
AI
Dev
Industry
Frontier
Updates in 60s
FN24 AI & Tech
View All →
Future News 24

The world's leading source for AI research, emerging technology, and the people building the future. Independent, rigorous, and always ahead.

CATEGORIES

  • AI Platforms & Apps
  • AI Research & Breakthroughs
  • BioTechnology
  • Data Science & MLOps
  • Decentralized Technology
  • Developer AI & Open-Source Ecosystem
  • Emerging Technologies & Innovations
  • Ethics & Policy
  • Industry & Business
  • Quantum Computing
  • Uncategorized

LATEST

  • [2602.13312] PeroMAS: A Multi-agent System of Perovskite Materials Discovery
  • GPT-6 Astra overview: code overview good points, privateness, and value
  • GPT-6 Astra: Options, Benchmarks, Pricing, and What’s New
  • About Us
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA 
  • Cookie Policy
  • Terms and Conditions
  • Contact us

© 2026 Future News 24. All rights reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • AI Research
  • Platforms
  • Ethics
  • Developer AI
  • Industry
  • Data Science
  • Emerging Tech
  • Quantum
  • BioTech
  • Decentralized

© 2026 Future News 24. All rights reserved.

Website security powered by MilesWeb