Microsoft’s August 2025 Patch Tuesday features security updates for 107 vulnerabilities, including a zero-day flaw in Windows Kerberos.
This Patch Tuesday addresses thirteen “Critical” vulnerabilities: nine related to remote code execution, three for information disclosure, and one for elevation of privileges.
By infosecbulletin
/ Saturday , September 12 2026
German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
By infosecbulletin
/ Friday , September 11 2026
GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
By infosecbulletin
/ Thursday , September 10 2026
Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
By infosecbulletin
/ Thursday , September 10 2026
Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
By infosecbulletin
/ Thursday , September 10 2026
Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
By infosecbulletin
/ Thursday , September 10 2026
A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
By infosecbulletin
/ Thursday , September 10 2026
Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
By infosecbulletin
/ Wednesday , September 9 2026
An unknown security expert called Nightmare Eclipse has drops a new Microsoft Defender flaw called "ShieldCrash" right after Microsoft released...
Read More
By infosecbulletin
/ Wednesday , September 9 2026
cPanel has shared CVE-2026-67401, a serious SQL injection flaw in EmailTrack. This flaw could allow attackers with permission to take...
Read More
By infosecbulletin
/ Wednesday , September 9 2026
An ongoing attack is focused on FortiGate firewalls. Hackers use a serious flaw to install a special Node.js remote access...
Read More
The number of bugs in each vulnerability category is listed below:
44 Elevation of Privilege Vulnerabilities
35 Remote Code Execution Vulnerabilities
18 Information Disclosure Vulnerabilities
4 Denial of Service Vulnerabilities
9 Spoofing Vulnerabilities
One publicly disclosed zero-day fixed:
This month’s Patch Tuesday addresses a publicly disclosed zero-day vulnerability in Microsoft SQL Server. A zero-day flaw is one that is known to the public or actively exploited without an official fix.
The publicly disclosed zero-day is:
CVE-2025-53779 – Windows Kerberos Elevation of Privilege Vulnerability
Microsoft has fixed a Windows Kerberos flaw that lets authenticated attackers obtain domain administrator privileges.
“Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network,” explains Microsoft.
Microsoft says that an attacker would need to have elevated access to the following dMSA attributes to exploit the flaw:
msds-groupMSAMembership: This attribute allows the user to utilize the dMSA.
msds-ManagedAccountPrecededByLink: The attacker needs write access to this attribute, which allows them to specify a user that the dMSA can act on behalf of.
SoupDealer Malware Bypasses Every Sandbox, AV’s, XDR/EDR in Real-World Incidents