Top stories.
- Patch Tuesday notes: Microsoft fixes three zero-days.
- Attackers target SharePoint vulnerability following PoC release.
- Business news: Visa and Deel both acquire identity verification companies.
Patch Tuesday notes: Microsoft fixes three zero-days.
Microsoft’s Patch Tuesday addressed a total of 421 vulnerabilities across its products, including Windows, Hyper-V, Microsoft Exchange Server, and Azure. Of these, 62 are rated critical and 357 are marked as important, with the most significant being three zero-day vulnerabilities. The zero-days include a tampering flaw in the Windows Container Isolation FS Filter Driver, an elevation of privilege bug in the Windows User Profile Service, and an actively exploited privilege escalation flaw in the Windows Ancillary Function Driver for WinSock. CISA has added the latter flaw to its Known Exploited Vulnerabilities Catalog, and ordered Federal agencies to apply patches by August 25th. Check Point has attributed the exploitation to North Korea’s Lazarus Group, in a campaign targeting the defense sector in Europe and India.
Adobe addressed 51 vulnerabilities across five of its products: Adobe ColdFusion, Adobe Commerce, Adobe Lightroom Classic, Content Credentials SDK, and Adobe Campaign Classic. Of these, 33 vulnerabilities are classified as critical.
SAP fixed 29 vulnerabilities, led by a maximum-severity flaw in SAP Commerce Cloud's Data Hub Adapter, CSO reports. This improper authorization issue allows unauthenticated remote attackers to submit crafted data, potentially leading to arbitrary code execution.
In the ICS space, Siemens, Schneider Electric, and Phoenix Contact released patches for various products, and CISA published advisories covering vulnerabilities in products from other vendors such as Pulsetto and Johnson Controls. Notably, Siemens issued a fix for a maximum-severity missing-authentication flaw in its Simatic IoT gateways, SecurityWeek notes.

