Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

2026-08-12T07:24:00Z587a8cf5ac6becbde1030c03cb523f7856faf3caf61a278ca2e8dfe13e5a2901
CVE-2026-55040CVE-2026-68820AI-securityDDoSKimsukyMCPMicrosoft SharePointNorth KoreaOT/ICSSandwormWindowsWordPressactive-exploitationbotnetcredential-theftcritical-infrastructuremalwarenation-statephishing-resistant-MFApower-gridprivilege-escalationprompt-injectionransomwareremote-code-executionsupply-chain-attackvulnerabilityzero-day

What happened

The document aggregates recent cybersecurity news covering actively exploited vulnerabilities, ransomware and botnet operations, supply-chain compromises, AI-assisted attacks, credential theft, critical-infrastructure intrusions, and nation-state campaigns. The highest-impact items include an unauthenticated SharePoint exploit chain reaching remote code execution (CVE-2026-55040, CVSS 9.1), an actively exploited Windows kernel driver privilege-escalation flaw (CVE-2026-68820, CVSS 7.0), and attacks against industrial and power infrastructure. Several reports describe emerging abuse of AI tools

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
587a8cf5ac6becbde1030c03cb523f7856faf3caf61a278ca2e8dfe13e5a2901
Enrichment time
2026-08-12T07:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.