
I check security news for work, which means most weeks I read about one bad thing and move on with my life. This week gave me five bad things, so now you all have to hear about it too.
Let’s start with the big one.
Microsoft’s August Patch Tuesday fixed 398 CVEs. Three hundred and ninety eight. I don’t know who’s counting these but I believe them. Buried in that number is a wormable DNS flaw that enables remote code execution, plus a separate zero-day that was already being actively exploited before the patch even shipped. “Wormable” is the word that should make you sit up. It means the flaw can spread machine to machine on its own, no clicking required, which is the same basic idea behind WannaCry back in 2017. If you’re the person who patches Windows infrastructure, congratulations, you know what you’re doing this week.
Next, Zoom, because apparently no piece of software gets to have a boring week. A bug in the annotation feature let a meeting participant run code on someone else’s machine, and it was zero-click. You didn’t have to open anything, click anything, or make any bad decisions. You just had to be in the meeting. Which is genuinely funny in a bleak way, because half of us are in meetings specifically to avoid doing anything, and it turns out that wasn’t even safe.
Then there’s the Defender situation, which I like less the more I think about it. A group calling themselves Chaotic Eclipse published a public proof of concept, cutely named ShieldBreak, that bypasses the patch for a Windows Defender zero-day and reportedly gets you SYSTEM-level code execution. So the fix for the hole got a hole in it, and now that hole has a name and a GitHub-adjacent following. Once a PoC like this is public, it stops being a theoretical problem and starts being a countdown.
SAP also shipped a patch batch, 28 new notes and 2 updated ones, four of them critical. Nobody is going to write a dramatic headline about SAP patches, which is exactly the problem, because that means it’s the one on this list most likely to get quietly ignored.
And on the less “fix your servers” and more “actual human impact” side, Unlimited Technology Systems reportedly had a breach exposing data tied to 3.8 million healthcare patients. I’ll flag that number is what’s being reported right now, not something I’ve seen confirmed in an official disclosure yet, so hold it loosely until more comes out.
Here’s the thing that actually stuck with me, once I stopped laughing about the Zoom bug. None of these are really separate stories. You’ve got a wormable OS-level flaw, a zero-click hole in software basically everyone has open eight hours a day, and a public bypass for the tool that’s supposed to catch exactly this kind of thing. That’s not five unrelated headlines, that’s one week where attacker tooling and defender tooling both moved, and defenders did not obviously win the week.
So patch the DNS thing first, assume “just a meeting app” is not out of scope anymore, and don’t be surprised if ShieldBreak shows up in something ugly sooner than later.
That’s the roundup. Try not to think about the 398 too hard.