Microsoft Patch Tuesday Addresses 418 Vulnerabilities Including Windows 0-Day Exploited by Lazarus Group
cybersecurityzero-dayvulnerabilitiesLazarus GroupNorth Koreadata leakmalicious extensionsIPMIBMC
During the week of August 10, 2026, Microsoft's Patch Tuesday addressed 418 vulnerabilities, including a Windows 0-day exploited by the Lazarus Group as part of Operation Dream Job. The North Korean threat actors targeted 1,640 companies using this unpatched flaw. Additionally, 3 million phone numbers were leaked from Bloctel, while 77 malicious extensions were discovered on Open VSX. A 20-year-old IPMI vulnerability left 86,000 Baseboard Management Controllers (BMCs) exposed, and the threat group Nightmare Eclipse disclosed another 0-day exploit.