Microsoft, Oracle Patches Highlight 2026 Zero-Day Surge
Microsoft and Oracle issued massive August 2026 patch rounds, including an actively exploited Windows zero-day and record vulnerability counts.
Open source software underpins nearly every layer of modern technology, from cloud infrastructure and enterprise platforms to mobile apps and AI systems. That ubiquity makes vulnerabilities in widely used libraries, frameworks, and dependencies a matter of global consequence: a single flaw buried deep in a software supply chain can ripple outward to affect thousands of organizations simultaneously. This hub tracks how those risks emerge, spread, and get resolved.
The topic matters more now than ever as attackers increasingly exploit identity systems, automate reconnaissance with AI, and target overburdened patch cycles. Enterprises face mounting pressure from record-breaking vendor patch releases, unresolved zero-days in critical business software, and the sobering reality that many essential open source projects are maintained by small, underfunded teams. That mismatch between reliance and resourcing has become a central theme in security conversations, prompting calls for better funding models, clearer maintainer support, and stronger accountability across the software supply chain.
Readers here will find ongoing coverage of newly disclosed vulnerabilities and the scramble to patch them, analysis of how threat actors—including AI-augmented adversaries—are shifting tactics toward identity-based attacks and software dependencies, and reporting on the economics and governance struggles facing open source maintainers. The hub also follows broader policy and industry responses, including sovereignty-driven initiatives to build alternative open models and infrastructure, as governments and enterprises reassess their reliance on shared code. Together, this coverage offers a continuous view into one of the most consequential and fast-evolving fronts in cybersecurity: the software the world depends on, and the fragile foundations that sometimes support it.
Microsoft and Oracle issued massive August 2026 patch rounds, including an actively exploited Windows zero-day and record vulnerability counts.
Multiple Windows zero-days, a Microsoft Defender bypass, and an exploited GeoServer flaw expose gaps in patching and disclosure practices.
A Microsoft Defender patch was bypassed by a new zero-day as researcher Nightmare Eclipse drops a tenth Windows flaw.
Researcher Nightmare Eclipse drops a 10th Windows zero-day amid Microsoft legal threats and a record 398-flaw Patch Tuesday.
Microsoft's August Patch Tuesday fixes a Windows zero-day under active attack among hundreds of other flaws.
Researcher Nightmare Eclipse published a Windows Defender zero-day, ShieldBreak, defying Microsoft's legal threats.
Microsoft, SAP, and Zoom all issued critical security patches in August 2026, including one actively exploited Windows flaw.
Microsoft's August Patch Tuesday fixed 421 bugs, including a Windows zero-day tied to Lazarus and North Korean hacking activity.
Apple, Microsoft, Oracle, and Samsung all issued major security updates, with AI-assisted discovery driving record patch volumes.
Microsoft's 167-patch update, including a SharePoint zero-day, highlights a wider surge in critical security fixes from Samsung, Zoom, and Oracle.
April 2026 saw zero-days hit Chrome, Adobe, Cisco FMC, and ShareFile, plus AI tools uncovering a new Apache flaw.
Delano, Minnesota schools canceled classes after a ransomware attack, amid wider trends in identity-based and AI-driven cyber threats.
cPanel, Oracle, Zoom, and Chrome all issued critical security patches this week, fixing flaws from SQL root escalation to account hijacking.
IBM reports data breach costs hit a record $4.99M as AI-enabled attacks rise, amid Amgen, DCPS, and Paidwork data exposures.
Broadcom, Oracle, Zoom, Zimbra, and Chrome all released critical security patches, with Oracle's 1,449-fix update setting a record.
A critical SharePoint zero-day joins Cisco, Arista, and AI-related flaws in a surge of actively exploited vulnerabilities.
IBM finds AI now drives 25% of breaches, as Suno's delayed 55.3M-user breach and a DCPS student data leak highlight 2026's security failures.
Sophos data shows 79% of ransomware attacks now start with compromised identities, as victim counts, gang rivalry, and AI targeting all surge in 2026.
CISA confirms active exploitation of chained SharePoint zero-days as Oracle ships a record 1,449 patches amid rising AI-driven vulnerability discovery.
Oracle shipped a record 1,449 security patches as SAP, Zimbra and Zoom also fixed critical flaws, highlighting industry-wide patch overload.
EXANTE warns that widely used open source software remains chronically underfunded despite being critical enterprise infrastructure.
Portugal released Amalia, its first open-source AI model, built by universities with EU funding to reduce reliance on US tech.