How an Emerging Industrial Protocol Family Could Put OT at Risk
New research shows how attacks against some unprotected TSN protocols could allow attackers to disrupt or manipulate physical processes
August 2026 brings a massive security update from Microsoft addressing 398 new CVEs alongside Adobe's release of 51 vulnerabilities, with critical flaws in DNS servers, deployment services, and QUIC protocol that require rapid testing and deployment, particularly for internet-facing infrastructure. While the volume of patches continues to grow as the new normal, only one Microsoft vulnerability is currently under active attack, allowing organizations to prioritize critical remote code execution bugs in DNS and QUIC over the broader patch load. Key priorities include Microsoft Exchange Server elevation-of-privilege vulnerabilities demonstrated at Pwn2Own, Windows Deployment Services TFTP flaws affecting PXE boot scenarios, and Adobe Campaign Classic issues, all rated for immediate deployment.
Read full article at Zero Day Initiative ↗New research shows how attacks against some unprotected TSN protocols could allow attackers to disrupt or manipulate physical processes
Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf
Microsoft has confirmed a maximum severity remote-code execution vulnerability in Entra ID that is being actively exploited in the wild. The company states the flaw has been fully mitigated and requires no further action from customers.
Researchers have identified a new attack technique called Cryptographic Context Injection that encrypts malicious instructions to evade safety guardrails in AI models including Grok and Gemini. The method works by concealing harmful prompts until they are decrypted within a trusted execution environment, effectively bypassing existing content filtering mechanisms. This vulnerability highlights a novel attack vector against popular large language models that defenders should monitor.