Urgent.News

What's breaking now, across thousands of outlets.

Tech

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Microsoft Plugs Nearly 400 Security Holes

Microsoft has released updates to address a record-breaking 398 security vulnerabilities in its Windows operating systems and supported software. Among these flaws, 42 were rated as critical, indicating that they pose significant risks that could be exploited by malware or malicious actors to gain remote control over Windows computers.

One of the vulnerabilities fixed is CVE-2026-68820, a privilege escalation weakness in the afd.sys driver that facilitates Windows socket connections. Another critical flaw is CVE-2026-62832, which also deals with privilege escalation and may be related to recent public disclosures by Nightmare Eclipse, a prolific bug hunter. The source notes that while AI has played a role in discovering these vulnerabilities, the actual patching of these issues remains a human-centric process.

The researcher Ed Skoudis emphasized that AI can be beneficial in finding vulnerabilities but fixing them requires human oversight, testing, and iterative improvements. Despite the recent deluge of patches, only one of the nearly 400 bugs patched this month is currently known to be actively exploited. Security leaders are advised to adjust their workflows to accommodate the increased patching workload and consider backing up their systems before applying these massive update bundles.

Written by urgent.news from KrebsOnSecurity's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at krebsonsecurity.com →

More in Tech

More from Tuesday 11 August →