Microsoft’s August 2025 Patch Tuesday features security updates for 107 vulnerabilities, including a zero-day flaw in Windows Kerberos.
This Patch Tuesday addresses thirteen “Critical” vulnerabilities: nine related to remote code execution, three for information disclosure, and one for elevation of privileges.
By infosecbulletin
/ Friday , October 2 2026
Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
By infosecbulletin
/ Thursday , October 1 2026
Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
By infosecbulletin
/ Wednesday , September 30 2026
Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
By infosecbulletin
/ Wednesday , September 30 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
By infosecbulletin
/ Tuesday , September 29 2026
Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
By infosecbulletin
/ Tuesday , September 29 2026
The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
By infosecbulletin
/ Tuesday , September 29 2026
The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
By infosecbulletin
/ Saturday , September 19 2026
Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
By infosecbulletin
/ Friday , September 18 2026
Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and one of three data-hosting zones in the...
Read More
By infosecbulletin
/ Friday , September 18 2026
A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
The number of bugs in each vulnerability category is listed below:
44 Elevation of Privilege Vulnerabilities
35 Remote Code Execution Vulnerabilities
18 Information Disclosure Vulnerabilities
4 Denial of Service Vulnerabilities
9 Spoofing Vulnerabilities
One publicly disclosed zero-day fixed:
This month’s Patch Tuesday addresses a publicly disclosed zero-day vulnerability in Microsoft SQL Server. A zero-day flaw is one that is known to the public or actively exploited without an official fix.
The publicly disclosed zero-day is:
CVE-2025-53779 – Windows Kerberos Elevation of Privilege Vulnerability
Microsoft has fixed a Windows Kerberos flaw that lets authenticated attackers obtain domain administrator privileges.
“Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network,” explains Microsoft.
Microsoft says that an attacker would need to have elevated access to the following dMSA attributes to exploit the flaw:
msds-groupMSAMembership: This attribute allows the user to utilize the dMSA.
msds-ManagedAccountPrecededByLink: The attacker needs write access to this attribute, which allows them to specify a user that the dMSA can act on behalf of.
SoupDealer Malware Bypasses Every Sandbox, AV’s, XDR/EDR in Real-World Incidents