LIVE · cybersecurity feed
Live wire
CVE-2026-68820

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

zeroday.news ·

Microsoft has reportedly issued its monthly security updates, addressing a substantial number of vulnerabilities, including a Windows kernel driver zero-day that is actively being exploited in the wild. This critical flaw is said to be present in a core Windows kernel driver responsible for managing network socket operations. The update package reportedly includes patches for 398 distinct vulnerabilities across various Microsoft products and services.

The zero-day vulnerability, identified as CVE-2026-68820 with a CVSS score of 7.0, is described as a privilege escalation flaw. It allows an attacker who has already established a foothold on a compromised system to elevate their privileges to SYSTEM level. This level of access grants an attacker extensive control over the operating system, potentially enabling them to install programs, view, change, or delete data, and create new accounts with full user rights.

The affected component is a fundamental Windows kernel driver, indicating its deep integration within the operating system's core functionalities. Kernel drivers operate at a highly privileged level, making vulnerabilities within them particularly dangerous as they can bypass many standard security controls. The specific function involved, network socket operations, suggests that the flaw could be triggered during network-related activities or by manipulating how the system handles network connections.

For this class of privilege escalation vulnerability, the typical attack vector involves an initial compromise through another means, such as phishing, exploiting a different application vulnerability, or social engineering. Once an attacker has user-level access, they can then leverage the kernel driver flaw to gain SYSTEM privileges. This "post-exploitation" phase is a common objective for adversaries seeking to establish persistent access and control over a target machine.

Mitigation for such issues generally involves prompt application of vendor-supplied security patches. Organizations are advised to prioritize the deployment of updates that address actively exploited vulnerabilities. Beyond patching, implementing a defense-in-depth strategy is crucial, which includes endpoint detection and response (EDR) solutions, robust network segmentation, least privilege principles for user accounts, and regular security awareness training to prevent initial compromises.

The discovery and active exploitation of a Windows kernel driver zero-day underscore the persistent threat landscape faced by users of widely adopted operating systems. Such flaws are highly prized by attackers due to their potential for significant impact and their ability to bypass traditional security measures. The rapid release of a patch by Microsoft highlights the urgency associated with addressing vulnerabilities that are actively being leveraged in real-world attacks, emphasizing the critical importance of timely patching for maintaining system security.

vulnerabilityzero-daypatchcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.

CVE-2026-58231critical

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.

vulnerability

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klonen.” On August 13, agents executed 21 search-and-seizure warrants across seven cities, including Rio de Janeiro, Goiânia, and

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.