Microsoft has resolved a bug that caused Windows Defender to crash after a recent security update, resulting in 0xc0000005 access violation errors on some affected systems. [...]

Microsoft has confirmed and resolved a bug that caused its Defender antivirus software to crash on some Windows 10 and Windows 11 systems. The issue, which began on Tuesday afternoon, August 19, 2026, manifested as "Threat service has stopped. Restart it now" error messages and 0xc0000005 access violation errors.
Users reported that quick or full scans would fail, sometimes requiring the Defender service to be restarted. One system administrator noted that they could reliably reproduce the issue by initiating a quick scan, even on clean systems. The widespread nature of the problem led some affected users to consider reinstalling their operating systems.
Microsoft stated that the bug has been addressed in a new signature update. The company recommends that users apply the latest update or ensure automatic updates are enabled. The fix is automatically applied upon installation of Microsoft Defender Antivirus signature update version 1.457.236.0 or later. Users are advised to update their systems via Windows Update and then verify that they have the most recent security intelligence update.
This incident follows other recent issues with Microsoft Defender. In May, system administrators reported that Defender incorrectly flagged DigiCert root certificate entries as Trojan:Win32/Cerdigent.A!dha malware, leading to numerous false-positive alerts and, in some instances, the removal of certificates from the Windows trust store. Prior to that, in December 2025, a widespread outage of the Microsoft Defender portal disrupted access to some Defender XDR portal capabilities and affected threat hunting alerts.

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs