Seite wählen

12.08.2026

Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability

CSO Online 12.08.2026 00:45
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases.
The hole is in Windows’ Ancillary Function Driver for WinSock (CVE-2026-68820), which, according to Todd Schell, principal product manager at Ivanti, has been a recurring target for local privilege-escalation bugs throughout 2026. Past vulnerabilities in this component have let an authorized attacker win a race condition to gain SYSTEM privileges.

Zoom zero-click RCE flaws allow attackers to compromise meeting participants

CSO Online 11.08.2026 22:56
Zoom has fixed four vulnerabilities across its applications, including two that could allow attackers who join a meeting to execute malicious code on the systems of all other meeting participants with no interaction required from them.
Three of the vulnerabilities affect all Zoom client applications for all platforms before versions 7.1.5 and 7.0.6, while the fourth impacts Zoom Workplace VDI Client for Windows and VDI Plugins on all supported platforms before versions 7.0.11 and 6.6.15. Products such as Zoom Rooms and Zoom Meeting SDK before versions 7.1.0 are also affected.

Microsoft Plugs Nearly 400 Security Holes

Krebs Security 11.08.2026 21:28
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

The Hacker News 11.08.2026 20:10
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.

The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first.

The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

Patch seit Mai verfügbar: Ransomware attackiert Microsoft Sharepoint

Heise Security 11.08.2026 19:39
Eine schwere Sicherheitslücke in Microsoft SharePoint wird nun von Ransomware ausgenutzt. Ein Patch steht bereit, ungeschützte Systeme auch.

Brandenburg: Cyberangriff legt IT-System der Gedenkstätten lahm

Heise Security 11.08.2026 16:43
Die Stiftung Brandenburgische Gedenkstätten wurde Opfer eines Ransomware-Angriffs. IT-Systeme sind derzeit außer Betrieb, ein Datenabfluss wird vermutet.

Patchday: SAP Commerce Cloud komplett kompromittierbar

Heise Security 11.08.2026 12:54
SAP schließt in seinem Softwareproduktportfolio mehrere unter anderem kritische Sicherheitslücken.

Kein Klick nötig: Plug-and-Pwn-Angriff kapert Windows-Systeme per USB

Golem 11.08.2026 11:45
Windows lädt beim Anschließen neuer USB-Geräte oft Software nach. Angreifer können dadurch Systemrechte erlangen – manchmal sogar aus der Ferne. (Sicherheitslücke, Treiber)

OpenAI launches GPT-5.6-Cyber as AI narrows vulnerability response window

CSO Online 11.08.2026 11:29
OpenAI has expanded its Daybreak cybersecurity program and introduced GPT-5.6-Cyber, a specialized model for approved security researchers, as the company warned that AI could give defenders less time to respond to developing threats.
Daybreak now has two access levels. Blue gives approved defenders access to frontier general-purpose models such as GPT-5.6 Sol for authorized defensive work, while Red provides specialized cyber models for more advanced activities, including vulnerability research, exploit validation, and security testing.

IBM Db2: Sicherheitslücke macht Passwörter im Klartext einsehbar

Heise Security 11.08.2026 09:52
IBMs Datenbanksystem Db2 ist über mehrere Schwachstellen angreifbar. Davon sind Client- und Serverversionen betroffen.

Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks

The Hacker News 11.08.2026 09:16
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world.

Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services.

"Gunra is another variant in the ongoing trend of

Sicherheitslücken: Angreifer können Wachdienst von ClamAV stören

Heise Security 11.08.2026 08:12
Der Open-Source-Virenscanner ClamAV ist verwundbar. Im schlimmsten Fall kann Schadcode auf Instanzen gelangen.

Hackers Breach Polish Power Plant Controls via Private Cellular Network and Shut Turbine

The Hacker News 11.08.2026 06:55
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment.

The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:30 a.m. while the intruders were still active inside the network, and customers lost neither heat