421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one

https://image.theregister.com/1683286.jpg?imageId=1683286&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

This is an epic month for Microsoft patches, though not a record-setting one. Redmond addressed 421 bugs in its own products this month - about 200 fewer CVEs than last month, but likely the new norm with AI-assisted vulnerability disclosures and fixes.

The big news is that North Korea’s Lazarus Group (and possibly other miscreants) found and attacked one of these flaws as a zero-day in early June.

The bug, tracked as CVE-2026-68820, is a use-after-free in the Windows Ancillary Function Driver for WinSock. “A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition,” Redmond warned, adding that successful exploitation could allow an attacker to execute code with SYSTEM-level privileges, and with no user interaction required.

Microsoft credited Check Point researchers Moshe Marelus and David Driker with finding and reporting CVE-2026-68820, and the security shop’s threat intel lead...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more

http://www.techmeme.com/img/techmeme_sq328.png

OpenAI VP of Global Policy Ann O'Leary says AI policy in the US is anchored in the states and informed by California's AI transparency law passed last year

More: Claude, Daring Fireball, import chaos, Fortune, City A.M., BMI, Quartz, Android Authority, Business Insider, The American Bazaar, The Deep View, iThinkDifferent, Breitbart, Neowin, RuntimeWire, The Daily Wire, The New Stack, CNET, Inc, Fast Company, Search Engine Land, Tech Brew, Michael Tsai, PYMNTS, SiliconANGLE, Forbes, WeRSM, Search Engine Journal,

https://images.ft.com/v3/image/raw/https%3A%2F%2Fd1e00ek4ebabms.cloudfront.net%2Fproduction%2F7523a6c6-0279-42eb-b2e3-7447048a2e24.jpg?source=next-barrier-page&fit=scale-down&quality=highe...

Researchers say suspected Chinese hackers used open-source AI agents to build an autonomous hacking tool that compromised Taiwanese government websites in July

More: Claude, Daring Fireball, import chaos, Fortune, City A.M., BMI, Quartz, Android Authority, The American Bazaar, The Deep View, iThinkDifferent, Breitbart, Neowin, RuntimeWire, The Daily Wire, The New Stack, CNET, Inc, Fast Company, Search Engine Land, Tech Brew, Business Insider, Michael Tsai, PYMNTS, SiliconANGLE, Forbes, Business Insider, WeRSM, Search