// Alert

Microsoft 365 threat report

Microsoft's August 2026 Patch Tuesday addresses 400+ vulnerabilities including CVE-2026-68820, a Windows Ancillary Function Driver elevation-of-privilege flaw actively exploited by North Korean threat actor Lazarus to deploy FudModule, a kernel-mode rootkit. Check Point disclosed the zero-day exploitation campaign. Two additional publicly disclosed zero-days (CVE-2026-62832 and CVE-2026-72971) were also fixed. Among critical flaws are remote code execution vulnerabilities in SharePoint (CVE-2026-65665), Windows DHCP (CVE-2026-62823), and Azure services.

// Get alerts for Microsoft 365