
Microsoft released its August patch last night, addressing 398 security vulnerabilities in Windows.
Key highlights:
• 42 “Critical” vulnerabilities — allowing remote control of the computer
• Zero-day CVE-2026-68820 in afd.sys, a core component of all Windows devices
• Hackers use it as a “step 2” — gaining entry via phishing first, then escalating to full Admin privileges
[Insight: The number 398 increased because AI is helping find vulnerabilities — July reached as high as 570. If your computer is never updated, please open Settings > Windows Update today. This zero-day does not execute on its own; it requires you to click a malicious link first.]
Kun Long
Author at The Sharing KH