Agregátor RSS
Hackers arrested over €30M bank fraud exploiting service provider flaw
Zákeřný malware zneužívá mobilní NFC platby v Česku. Útočníci si přes něj mohou sjednat půjčku na vaše jméno
1.6M RingCentral accounts' data dumped after ShinyHunters extortion attack
Windows 11 čeká dieta a dřina. Microsoft chce okna zeštíhlit i zrychlit (Podcast Živě)
Windows 11 čeká dieta a dřina. Microsoft chce okna zeštíhlit i zrychlit (Podcast Živě)
August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw
Microsoft’s August 2026 Patch Tuesday closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). Two more were disclosed but not exploited, CVE-2026-62832 (User Profile Service) and CVE-2026-72971.
This security-only release earns Patch Now for Windows, Office and Exchange; no SQL Server updates this month. Unfortunately, several critical issues affect server roles: Windows DNS Server carries a cluster of critical RCEs; Windows DHCP Server is the most-populated Microsoft product family at 14 entries. Testing should lead with printing and fonts and the Remote Desktop client, then a WinSock smoke test given the exploited afd.sys flaw. The Readiness team has provided a helpful infographic on the deployment risks for this Microsoft August update.
Known issuesBoth August client and server-side updates ship with empty known-issues lists. This may change over the coming days so checking back to the Microsoft Security Update Guide (MSRC) may be prudent. July’s open items have all closed: the Dell/Intel driver hold, the mid-July WSUS sync degradation, and the Emoji Panel GIF outage (August swaps in GIPHY).
- On the server side, WSUS synchronisation error details stay suppressed. The August Windows Server 2025 (KB5120233) and 2022 (KB5120242) updates still list this, the detail pane removed to address a remote code execution flaw CVE-2025-59287, with no published workaround.
One July item has been dropped from the documentation without a resolution note: the Windows Server 2022 BitLocker recovery prompt on first restart, for hosts carrying the PCR7 Group Policy condition. With no fix published, the Readiness team recommends that all recovery keys are (easily) retrievable before restarting freshly patched servers.
Major revisions and mitigationsBetween the July and August Patch Tuesdays (15 July to 10 August), the MSRC Security Update Guide revised 534 CVEs. Almost all these changes (458) were routine Microsoft Edge and Chromium re-publications – none of which required customer action. That leaves 76 touching Microsoft’s own products, 60 of them flagged customer action required, including:
- Windows storage and file system: four NTFS entries, all three July ReFS elevation-of-privilege flaws, and two Brokering File System fixes.
- Identity and federation: six AD FS denial-of-service CVEs, plus two Azure Active Directory entries.
- Developer runtimes: nine .NET and .NET Framework CVEs, with PowerShell and ASP.NET Core alongside.
The Readiness team has reviewed the 751 published updates, and it appears that Microsoft has not published any mitigations for updates in this August release.
Windows lifecycle and enforcement updatesMicrosoft has not published any service or enforcement deadlines for this August. The 13 October 2026 cluster stacks five migration tracks onto one date, with a second wave on 10 November; dates below come from the linked Microsoft lifecycle pages.
- Windows Server 2012 and 2012 R2 ESU hits year three. Windows 10 2016 LTSB reaches the end of extended support, and Office LTSC 2021 and retail Office 2021 all end 13 October.
- Windows Server 2022 drops to extended support on 13 October 2026, security-only to 14 October 2031.
One diary note: Windows 11 24H2 Home and Pro reach end of updates on 13 October 2026, two Patch Tuesdays out.
Microsoft’s August 2026 Patch Tuesday is a security-only release: 109 Windows test-guidance entries, four High Risk (July had 14). Printing and fonts lead: win32kfull.sys is the most-patched binary at seven entries and carries three of the four High Risk flags (32-bit printing on 64-bit Windows and font rendering); the Remote Desktop client carries the fourth. The testing guidance below works through each product and feature grouping.
Printing, fonts and graphicsThree of the four High Risk flags sit in win32k and touch print or font paths: 32-bit application printing on 64-bit Windows (two) and font rendering (one). GDI+, the Windows Imaging Component, and the kernel graphics driver (dxgkrnl.sys, five entries) change alongside; estates with 32-bit line-of-business printing or font-heavy documents take this first.
- Print from your 32-bit applications to physical and virtual (PDF or XPS) printers, using text-heavy, graphics-heavy, and multi-page documents, and repeat after each relaunch, orientation, scaling, and resolution change.
- Render varied fonts, sizes, and styles across browsers, Office, PDF viewers, and Notepad, and confirm Print Preview matches the printed page – watch for clipping, distortion, or missing glyphs.
- Copy and paste images between Paint, Word, and Excel at different bit depths, and open EMF and TIFF files.
- Exercise the graphics kernel: full-screen DirectX, multi-monitor hot-plug, resolution, HDR, and DPI changes, and sleep/resume.
The RDP client carries the fourth High Risk flag; the fixes touch every redirection path and multi-session behaviour. RemoteApp, the display pipeline, and the RRAS and SSTP VPN stack change alongside.
- Open several concurrent RDP sessions, enable printer, clipboard, audio, drive, and smart card redirection together, and exercise each across the sessions, confirming none interferes with another.
- Disconnect and reconnect a session, confirm redirected devices and drives reattach, and test a RemoteApp end to end.
- Configure a standard client VPN and an SSTP VPN over HTTPS and confirm sustained connections across reconnects and a restart.
The SMB client and server, NTFS and UDFS, the virtualised file layers (Cloud Files, Projected File System, Work Folders), and the platform stack (Hyper-V, virtual TPM, USB, and Windows Installer) all change. Standard Risk.
- Connect to SMB shares (including RDMA, leases, and Continuous Availability), copy large sets both ways, and interrupt and reconnect a session; exercise NTFS extended attributes, UDF mounts, and cloud-file hydrate and dehydrate.
- Create, checkpoint, and export a Generation 2 Hyper-V VM, enable a virtual TPM and BitLocker, and connect USB storage and MIDI devices.
- Install, repair, and uninstall an MSI package, and confirm UAC elevation still prompts.
TAPI is the busiest component (11 entries) but carries only parity fixes; the rest spans TCP/IP, HTTP.sys, Windows Firewall, Bluetooth, wired 802.1X, and message queuing. Broad and shallow.
- Exercise TAPI line status and dialling locations against a shared line, and verify HTTP.sys under IIS over HTTP/1.1, HTTP/2, and HTTP/3.
- Confirm TCP/IP IPsec tunnels on IPv4 and IPv6, toggle Windows Firewall rules across a restart, pair a Bluetooth headset, authenticate wired 802.1X, and validate MSMQ send and receive.
This August patch cycle affects click-to-run (C2R), Microsoft 365 Apps, and MSI deployments of Microsoft Office with the following updates:
- On MSI Office 2016, apply the client updates: Access (KB5002813), the ACE database engine (KB5002832), the Office proofing and UI components (KB5002791, KB5002795), Outlook (KB5002755), VBA (KB5002900), and Word (KB5002901), then exercise macros, external data, embedded objects, and line-of-business add-ins.
- On SharePoint Server, patch 2016, 2019, and Subscription Edition, then check browser-based editing; mind the rollback rules – server updates cannot be uninstalled and always require a reboot.
On-premises Exchange takes a security update this month, seven CVEs across Exchange Server 2016, 2019, and Subscription Edition: one critical elevation of privilege and six important, spanning further elevation of privilege, remote code execution, denial of service, spoofing, and a security feature bypass.
- Apply the update from an elevated command prompt: an un-elevated run leaves Exchange services partially patched and broken. Then confirm every Exchange service returns and that the server reports healthy.
- Exercise mail flow end to end: send and receive internal and external mail, drain the transport queues, and check connectors and transport rules; confirm Outlook (MAPI over HTTP), Outlook on the web, and the Exchange admin centre for sign-in and core actions.
- Confirm Autodiscover and free/busy resolve, test any hybrid connection to Exchange Online, and plan for the reboot the update requires – validate in a maintenance window before production.
The developer estate gets a broad, low-drama sweep; no SQL Server this month. Both the .NET Framework (Windows Server 2012 to Windows 11 26H1 and Server 2025) and the modern runtime and SDK patch, including WPF and WinForms.
- Install the .NET Framework and modern .NET runtime and SDK updates, run a representative set of WPF, WinForms, web, and command-line applications, confirm normal behaviour, and build and run a .NET project to check for regressions.
The Readiness team recommends the following priorities for your larger enterprise deployments:
- Start with printing and fonts: three of the four High Risk flags sit in win32k, so regress 32-bit printing, PDF and XPS export, font rendering, and Print Preview before anything else.
- Take Remote Desktop next, the fourth High Risk flag, across the redirection paths, concurrent sessions, reconnects, RemoteApp, and SSTP VPN.
- Give the busy but lower-risk areas a smoke pass: Telephony, the graphics kernel, DNS and DHCP, Active Directory, and the SMB stack.
- Close out the rest: Office spans MSI 2016, SharePoint and Microsoft 365 Apps this month (Click-to-Run is in scope, unlike July), and .NET is a representative-application check.
Each month, we break down the update cycle into product families, as defined by Microsoft, with the following groupings.
BrowsersAfter July’s 46-strong Microsoft Edge (Chromium-based) haul, the browser family has nothing to report: August’s Security Update Guide carries no Edge-specific CVEs at all. It’s Margarita time – look busy or look elsewhere for patch-related testing and deployments.
Microsoft WindowsWindows carries the bulk again: 233 CVEs, 18 critical, the rest important bar one moderate. Elevation of privilege leads by volume (143 entries), but all but two of the 18 are rated as critical remote code execution vulnerabilities, on the network-facing server roles.
- DHCP and DNS lead the critical-rated issues. Windows DHCP Server takes 14 CVEs, the busiest component by far, topped by a critical remote code execution flaw (CVE-2026-62823, “Exploitation More Likely”), with DHCP Client adding four more. Windows DNS Server is the headline RCE risk: six entries, four of them critical (CVE-2026-62878, CVE-2026-62817, CVE-2026-62820, CVE-2026-65789), reaching back to Server 2012. Patch the resolvers alongside the DHCP boxes.
- A wider critical cluster. Beyond DNS, critical-rated issues also reach Microsoft QUIC, RRAS, the iSCSI Target Service, the WDS TFTP Server, the Remote Desktop Client, GDI+ graphics and Active Directory Certificate Services; domain controllers take priority, and Print Spooler and WSUS are for once absent.
- Most-patched tally. DHCP Server leads (14, one critical), Win32k next (13 across two groupings), then the Telephony Service (11), the DNS client resolver (10), Windows Installer (nine), and the Windows Kernel and NTFS (eight each).
Add this Windows update to your Patch Now schedule, with your DHCP and DNS servers updated first.
Microsoft OfficeMicrosoft released 120 Office CVEs this month, 24 of them critical, remote code execution the through-line (62 entries). The packaging work sits on MSI Office 2016 and the SharePoint farms, but the exposure is overwhelmingly Click-to-Run: 89 of the 120 list Microsoft 365 Apps for Enterprise as affected, 20 of them critical, straight through the update channel.
- Office clients – the critical RCE runs across Office, Word and Excel, mostly in document-rendering paths that fire on preview or open. The top-rated critical client entry, CVE-2026-70130, lists Microsoft 365 Apps among its affected builds, so Click-to-Run estates are squarely in scope rather than sitting this one out, as they could in July.
- SharePoint Server – three critical-rated vulnerabilities on the on-premises farms, led by CVE-2026-65665, an RCE rated “Exploitation More Likely” (2019 and Subscription Edition), with two critical elevation-of-privilege entries behind it; a separate SharePoint Online spoofing flaw is fixed service-side.
Nothing in Office is exploited this month, but that critical SharePoint RCE and 20 Click-to-Run critical-rated vulnerabilities argue against waiting. Add the August Office and SharePoint updates to your Patch Now schedule.
Microsoft Exchange and SQL ServerExchange Server has seven CVEs across Exchange Server 2016, 2019 and Subscription Edition, as four build-specific updates (KB5121573 through KB5121576). One is critical and six important; none is disclosed or exploited, but Exchange is internet-facing, so we would not wait.
- Exchange Server (on-premises) – the critical entry is an elevation of privilege (CVE-2026-62911); the heaviest of the rest is a remote code execution (CVE-2026-62913). Apply it from an elevated command prompt and plan for the reboot (the test-guidance section covers mail-flow). Subscription Edition is the go-forward release; 2016 and 2019 still being carried is a reprieve, not grounds to defer migration.
- SQL Server – nothing to install. On-premises SQL Server ships nothing; the only SQL-branded entries are cloud-side Azure SQL fixes, resolved service-side.
Add the on-premises Exchange update to your Patch Now schedule; SQL Server does not require anything this month.
Microsoft developer toolsMicrosoft released 23 CVEs across its developer tooling this month, all rated as important: 13 in .NET and the .NET Framework, and 10 across Visual Studio Code and its Copilot extensions.
- Microsoft .NET and .NET Framework – the runtime and framework are the focus this month, led by two remote code execution entries (CVE-2026-62897, .NET Framework, and CVE-2026-70354, .NET Core). The Framework rollups span Windows Server 2012 to Windows 11 26H1 and Server 2025; Visual Studio 2022 17.14 and 2026 18.8 take their exposure through the bundled runtime.
- Visual Studio Code and Copilot – have three remote code execution entries and security feature bypasses across the Python extension, Copilot Chat and the core editor.
Add these developer-focused updates to your standard release schedule, behind this month’s Windows and Office priorities.
Adobe (and third-party updates)Unusually, Adobe published an early-August emergency fix for a maximum-severity Adobe flaw (CVE-2026-48449), an incorrect authorisation that runs code with no user interaction. This makes this an Adobe “whatever you have installed” Patch Now moment due to how Adobe tends to share code between products. This August, there were two third-party flaws on Microsoft’s third-party list: the Trusted Computing Group’s TPM 2.0 reference-code bugs CVE-2026-6726 and CVE-2026-6727, both Important and issued by MITRE. If unpatched, a local attacker with TPM command access can work back to keys the chip should keep sealed, up to the RSA Endorsement Key behind device attestation. This completely defeats the purpose of the TPM chip – and, some would say, of migrating to Windows 11. Sorry, not sorry.
Máme Pixel 11 Pro a začínáme testovat. Google letos inovace odměřil na lékárnických vahách
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Google dotírá na Claude a GPT cenou i schopnostmi. Rychle připravil schopný model Gemini 3.7 Flash
Ploopy A+ Trackball
OpenAI and Anthropic in price war as Chinese AI rivals gain ground
Leading US AI labs such as OpenAI and Anthropic are releasing cheaper models as they fight to retain cost-conscious customers who are switching to cut-price alternatives from Chinese rivals.
The price war comes as rising AI bills push companies to curb usage and seek cheaper models, helping Chinese developers including Moonshot and DeepSeek make inroads with users from Silicon Valley to Europe.
OpenAI recently said that it was slashing prices for GPT-5.6 Luna, its “fastest and most affordable model”, by 80 percent. Anthropic has launched Claude Opus 5, touting the system’s “frontier intelligence... at half the price” of Fable 5, the company’s most capable model.
French tax authority admits data heist after crook touts 2M records
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
Linux BPF Patches Fix Sparse CPU Bugs Causing Out-of-Bounds Read
Max severity SAP Commerce Cloud flaw now targeted in attacks
Okénko Boeingu 737, které nasálo cestujícího, rozbila lopatka motoru. Prostudovali jsme předběžnou zprávu
OpenAI loses its AI ethics lead
OpenAI has lost its AI ethics lead Chloé Bakalar just a year after she joined the company, the Financial Times reported. Bakalar has maintained a silence and has yet to update her LinkedIn profile, but if her departure is confirmed then it will add to the list of OpenAI executives who have quit in recent months.
Other departures include robotics chief Caitlin Kalinowski, who left the company over its deal with the US Department of Defense; researcher Zoe Hitzig, who quit in a very public way by writing an article in the New York Times; and Johannes Heidecke, head of safety systems.
OpenAI’s ethical stance has been called into question following an attack by OpenAI models on Hugging Face.
The departure of its sole ethicist will add to the pressure on the company. In her year at OpenAI Bakalar focused on ethical approaches to model development, looking at how humans interact with AI and examining machine consciousness, according to the FT report.
Bakalar had considerable expertise in the area. She was previously at Meta, where she developed the company’s ethics programs, but has also held several positions at prestigious universities on both sides of the Atlantic. Her departure will cause some anxiety at OpenAI as it continues to prepare the ground for its IPO.
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
Meta gives up control of Chinese AI startup Manus after eight months
Chinese AI company Manus has laid out its plans to operate as an independent company following the reversal of its acquisition by Meta.
The US social media company agreed to buy Manus last year but Chinese regulators quickly opened an investigation into the deal, as they were concerned that it violated Chinese export controls. In April, China’s National Development and Reform Commission blocked the purchase.
Manus will now revert to being an independent company and to meet with regulatory requirements must delete some user data collected while it was part of Meta, it said Tuesday.
The failure of the deal illustrates the problems that US and Chinese companies are having as they attempt to build a hold on the AI market.
While regulatory authorities in China don’t want Manus under US ownership, US authorities are equally suspicious of China’s role in AI development. The US administration fired a warning shot this March by unveiling a new cybersecurity policy, a move which was prompted by suspected Chinese involvement in a cyber-attack on the FBI.
Also in March, the US-China Economic and Security Review Commission warned that Chinese use of open-source AI tools could lead to an economic advantage that the US couldn’t counter through regulation. And last year, US and Chinese authorities played a cat-and-mouse game over Nvidia chip exports.
Customers of AI vendors in both countries may need to be wary about future cross-border acquisitions as the two superpowers jostle for a technological lead.
Autonomous AI attacks pose 'clear and present danger' to critical infrastructure
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- …
- následující ›
- poslední »



