← Back
VulnerabilityZero Day Initiative·1 week ago

The August 2026 Security Update Review

August 2026 brings a massive security update from Microsoft addressing 398 new CVEs alongside Adobe's release of 51 vulnerabilities, with critical flaws in DNS servers, deployment services, and QUIC protocol that require rapid testing and deployment, particularly for internet-facing infrastructure. While the volume of patches continues to grow as the new normal, only one Microsoft vulnerability is currently under active attack, allowing organizations to prioritize critical remote code execution bugs in DNS and QUIC over the broader patch load. Key priorities include Microsoft Exchange Server elevation-of-privilege vulnerabilities demonstrated at Pwn2Own, Windows Deployment Services TFTP flaws affecting PXE boot scenarios, and Adobe Campaign Classic issues, all rated for immediate deployment.

Read full article at Zero Day Initiative

Related Articles

VulnerabilitySecurityWeek·2 days ago

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

Researchers have identified a new attack technique called Cryptographic Context Injection that encrypts malicious instructions to evade safety guardrails in AI models including Grok and Gemini. The method works by concealing harmful prompts until they are decrypted within a trusted execution environment, effectively bypassing existing content filtering mechanisms. This vulnerability highlights a novel attack vector against popular large language models that defenders should monitor.