421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one
- ID
- 13335
- Status
- summarized
- Published
- 12 Aug 2026, 5:31 AM
- Fetched
- 12 Aug 2026, 12:13 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/08/11/421-bugs-in-microsofts-patch-tuesday-release-and-the-norks-have-already-attacked-one/5286483
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.0
- Created
- 12 Aug 2026, 12:14 PM
- Tags
- Audience
- developers
What happened
Microsoft's August 2026 Patch Tuesday fixed 421 vulnerabilities, down ~200 from the prior month but described as the new norm under AI-assisted disclosure. One of them, CVE-2026-68820, was already exploited as a zero-day by North Korea's Lazarus Group since early June—a use-after-free in the Windows Ancillary Function Driver for WinSock allowing SYSTEM-level code execution by a locally authenticated attacker with no user interaction.
Why it matters
If you manage Windows desktops or servers, patch immediately—CVE-2026-68820 is a local privilege escalation already weaponized by Lazarus in Operation Dream Job social-engineering campaigns targeting defense-sector job seekers in Europe and India. For most cloud-native or Linux-based builders in this community, there is no direct action; the bug requires local authentication and the attack chain targets a specific sector.
Discussion angle
The article claims AI-assisted vulnerability disclosure is making 400+ CVE months the 'new norm'—worth discussing whether this changes how teams should triage patch volume versus focusing only on actively exploited flaws.