Tag

Patch Tuesday

All articles tagged with #patch tuesday

Microsoft urges Windows 11 users to update within 3 days as 400+ fixes roll out
technology10 days ago

Microsoft urges Windows 11 users to update within 3 days as 400+ fixes roll out

Microsoft’s August 2026 Patch Tuesday delivers a Windows 11 update with 400+ fixes (421 across Edge, Teams, and other products), including several critical remote code execution and privilege-elevation fixes. The company warns users to install within three days and to verify they’re on Build 26200.9168 (25H2) or 26100.9168 (24H2) before updating; KB5121003 may require up to two reboots due to Secure Boot.

NightmareEclipse Unleashes Windows Defender Zero-Day Ahead of Patch Tuesday
security11 days ago

NightmareEclipse Unleashes Windows Defender Zero-Day Ahead of Patch Tuesday

Security researcher NightmareEclipse has published ShieldBreak, a new Windows Defender zero-day that allegedly lets attackers gain full control of a Windows device and may bypass the RoguePlanet patch (CVE-2026-50656). Microsoft is investigating but has not confirmed the claims; external researchers say the POC is legitimate. Tests reportedly work on Windows 11 25H2, Windows Server 2025, and even Windows 10. The disclosure comes ahead of Patch Tuesday, continuing the feud between Microsoft and the researcher over Windows security.

Patch Tuesday hits 421 fixes as Lazarus exploits a new zero-day
cybersecurity13 days ago

Patch Tuesday hits 421 fixes as Lazarus exploits a new zero-day

Microsoft’s August Patch Tuesday patches 421 CVEs, including CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock that North Korea’s Lazarus Group allegedly weaponized as a zero-day in June. Analysts link the campaigns to the Dream Job operation, which uses fake defense-industry job sites and a Trojanized PDF viewer called SecurityPDF delivered via phishing to install the backdoor Troy. Other notable fixes include CVE-2026-62832 (privilege escalation via loading another user’s registry hive) and CVE-2026-62893 (Windows Deployment Services TFTP remote code execution), among others highlighted by researchers and ZDI.

security13 days ago

Microsoft Patch Tuesday Deluge: 398 Flaws Fixed, Zero-Day in afd.sys Exposed

Microsoft released a massive Patch Tuesday, fixing 398 vulnerabilities across Windows and related software, including a zero-day in afd.sys (CVE-2026-68820) and two other publicly disclosed flaws; 42 fixes are critical. AI aided vulnerability discovery, but patching remains heavily human-driven and requires testing. Users should back up data and deploy updates cautiously, as large update bundles may take time to stabilize.

Microsoft Deploys Massive August 2026 Patch Tuesday to Close 400 Flaws, Three Zero-Days
security13 days ago

Microsoft Deploys Massive August 2026 Patch Tuesday to Close 400 Flaws, Three Zero-Days

Microsoft’s August 2026 Patch Tuesday patches roughly 400 vulnerabilities across a broad Microsoft stack, including three zero-days. The fixes span Windows, Office, Azure, Exchange, SharePoint, SQL, PowerShell, and more, with many critical remote code execution and elevation-of-privilege flaws addressed. Organizations should apply the updates promptly to reduce exposure to exploitation.

August 2026 Windows 11 Patch Tuesday Welcomes KB5121003 and KB5120240 with 400 Fixes
technology13 days ago

August 2026 Windows 11 Patch Tuesday Welcomes KB5121003 and KB5120240 with 400 Fixes

Microsoft released Windows 11 cumulative updates KB5121003 and KB5120240 for versions 25H2/24H2/23H2 as part of the August 2026 Patch Tuesday, addressing around 400 security vulnerabilities and delivering a broad set of improvements across components like File Explorer, Windows Search, Voice Access, Widgets, Touchpad, Start menu, Windows Hello ESS, fonts, and accessibility. The updates are mandatory and apply to all affected versions; installation can be done via Settings > Windows Update or the Microsoft Update Catalog, with fixes shared across the listed Windows 11 versions.

Windows 11 August 2026 Patch Tuesday adds AI controls, ESS sign-in, and quality-of-life refinements
technology27 days ago

Windows 11 August 2026 Patch Tuesday adds AI controls, ESS sign-in, and quality-of-life refinements

Microsoft’s August 2026 Patch Tuesday for Windows 11 brings a broad polish pass: Windows Hello Enhanced Sign-in Security now supports external fingerprint sensors; an option to uninstall the AI-generated Image/AI model from Copilot+ PCs; plus a slate of improvements across File Explorer, Windows Search, Widgets, and Windows Update. Other updates include new touchpad gestures, better Voice Typing/Voice Access with noise isolation, a redesigned Account Control flyout, and power/battery tweaks. The update also returns the ability to set Energy Saver battery percentage and delivers more accurate update progress. These changes apply to Windows 11 versions 25H2 and 24H2 (identical) via Controlled Feature Rollout.

AI-Driven Patch Tuesday Expands Windows 11 Update with 570 Fixes
technology1 month ago

AI-Driven Patch Tuesday Expands Windows 11 Update with 570 Fixes

Microsoft’s July 2026 Patch Tuesday for Windows 11 patches 570 vulnerabilities across Windows core components, including the Windows Kernel and Remote Desktop, marking one of the largest security updates in the OS’s history. AI-assisted tools like MDASH help identify and validate issues earlier, suggesting future updates will be larger but more comprehensive as AI accelerates vulnerability discovery. Microsoft emphasizes timely installation to counter faster exploitation, while non-security improvements accompany the update.

CISA adds SharePoint zero-day to KEV, agencies told to patch by July 19
security1 month ago

CISA adds SharePoint zero-day to KEV, agencies told to patch by July 19

CISA added CVE-2026-58644, a critical deserialization RCE in Microsoft SharePoint Server, to the Known Exploited Vulnerabilities catalog, with FCEB agencies required to patch by July 19, 2026. Microsoft said the flaw was exploited in the wild before fixes were released (patches issued July 14, 2026). The warning comes as CISA notes ongoing exploitation of multiple on-premises SharePoint vulnerabilities and urges hardening steps: apply patches, enable AMSI, scan for intrusion artifacts, tailor logging, and avoid exposing SharePoint servers to the internet.

Dell PCs hit by July Windows 11 patch as Microsoft blocks rollout pending fix
technology1 month ago

Dell PCs hit by July Windows 11 patch as Microsoft blocks rollout pending fix

Microsoft has blocked the July 2026 Windows 11 security update KB5101650 on certain Dell PCs after reports of unexpected shutdowns, overheating, and battery drain caused by a conflict with the Intel Innovation Platform Framework Processor Participant driver linked to the June 2026 optional update KB5095093. The update, which patches 570 security flaws, is being withheld on affected devices while Microsoft and Dell work on a fix.

Microsoft Patch Tuesday Breaks Record With 622 CVEs, Two Zero-Days Under Active Exploitation
technology1 month ago

Microsoft Patch Tuesday Breaks Record With 622 CVEs, Two Zero-Days Under Active Exploitation

Microsoft’s July Patch Tuesday patches a record 622 CVEs, including two zero-days that are already being exploited: CVE-2026-56164 in on-premises SharePoint Server (unauthenticated remote privilege escalation) and CVE-2026-56155 in AD FS (local privilege escalation). The release also includes a BitLocker bypass (CVE-2026-50661) and numerous other fixes. Administrators should audit RC4 usage, rotate affected service accounts, and prioritize patches for Windows, SharePoint, and AD FS, noting that SharePoint 2016/2019 reach end of extended support.

Windows 11 July 2026 Patch Tuesday unlocks new features and offers direct offline installers (.msu)
technology1 month ago

Windows 11 July 2026 Patch Tuesday unlocks new features and offers direct offline installers (.msu)

Microsoft’s Windows 11 July 2026 Patch Tuesday release KB5101650 is rolling out via Windows Update and is also available as direct offline installers (.msu). The update is mandatory and brings several minor features and stability fixes, including Bluetooth improvements, a new Point-in-time restore recovery option, easier update deferral for Home editions, a quieter Widgets board, Screen Tint accessibility, faster File Explorer, configurable touchpad right-click size, and IPP printer support. It also includes .NET security updates and a Windows Malicious Software Removal Tool update; build numbers are 26200.8875 (25H2) and 26100.8875 (24H2), with offline installer sizes around 4.8–5.4 GB. Microsoft notes the end of support for Windows 11 24H2 in 2026, so upgrading is advised, and warns against delaying updates more than three days due to AI-driven threats.

technology-security1 month ago

Microsoft patches a record 570 flaws in AI-augmented Patch Tuesday

Microsoft released a record Patch Tuesday fixing at least 570 vulnerabilities across Windows and related software, driven by AI-driven vulnerability discovery; about 60 are critical and three zero-days are already being exploited. Highlights include CVE-2026-56155 (Active Directory Federation Services), CVE-2026-56164 (SharePoint), and CVE-2026-50661 (BitLocker bypass), plus a Copilot remote code execution flaw (CVE-2026-48561). Industry experts warn exploitability ratings may lag AI-enabled discovery as patch cadences rise across vendors. Users are advised to back up systems and consider delaying updates if stability is a concern.

Microsoft patches 570 flaws in July 2026 Patch Tuesday, including three zero-days
technology1 month ago

Microsoft patches 570 flaws in July 2026 Patch Tuesday, including three zero-days

Microsoft’s July 2026 Patch Tuesday fixes roughly 570 vulnerabilities across Windows, Office, Azure, and related services, including three zero-days. The updates cover remote code execution, elevation of privilege, spoofing, and information disclosure across a wide range of components such as AD DS, RDP, Office apps, and core OS subsystems, so applying these patches promptly is essential to reduce exposure.

AI-Driven Flaw Hunting to Drive More Windows Security Patches
technology1 month ago

AI-Driven Flaw Hunting to Drive More Windows Security Patches

Microsoft says AI-powered vulnerability discovery is accelerating the identification of Windows flaws, leading to more security updates in each Patch Tuesday. Its MDASH system scans critical Windows binaries, validates findings with multiple AI models, and reduces false positives before engineers review and ship fixes. The company is also updating Secure Development Lifecycle practices to account for AI-enabled attacks, and CISA is using Anthropic's Fable AI for government software audits, highlighting a broader trend toward AI-assisted cybersecurity.