ZeroHour
Vendor

MITRE

0 mentions in 7 days · 1 in 30 days · 2 total · first seen · last

Timeline

Evidence-Grounded Retrieval for Investigation Hunt Lead Generation from CTI Reports

AHLERT generates environment-aware threat hunting leads from CTI reports using ATT&CK-seeded knowledge graph retrieval, roughly doubling F1 over flat-RAG baselines.

The paper introduces AHLERT, a system that converts Cyber Threat Intelligence reports into structured, investigable hunt leads via hybrid dense retrieval with multi-hop traversal over an MITRE ATT&CK-seeded knowledge graph and ontology-grounded RAG constrained to the defender's assets. It is LLM-agnostic and evaluated on public CTI reports for well-known APTs across proprietary and open-weight models. Hybrid evidence retrieval with ontology grounding raises mean F1 from 0.44 to 0.85, and AHLERT attains the highest effectiveness score (~86.95%) versus off-the-shelf LLMs.

arXiv cs.CR · 7d agoResearch

Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)

Tenable reports Microsoft's August 2026 Patch Tuesday addresses 398 CVEs including three zero-days, one exploited in the wild (CVE-2026-68820).

Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 important, and one moderate, and three zero-days among them. One zero-day is confirmed as exploited in the wild. The release covers components including .NET, .NET Framework, Active Directory Certificate Services (AD CS), Azure services, and Windows. Tenable's count omits two CVEs assigned by MITRE, CVE-2026-6726 and CVE-2026-6727.

Tenable Blog · Aug 11, 2026Vulnerability in the wildCVE-2026-68820CVE-2026-6726CVE-2026-67271

Related CVEs

  • Use-After-Free Local Privilege Escalation in Microsoft Windows WinSock AFD Driver
    CVE-2026-68820 is a use-after-free (CWE-416) in the Windows Ancillary Function Driver for WinSock (afd.sys), the kernel component that handles Winsock socket operations. A local, authenticated attacker can trigger the memory corruption through crafted socket activity, and the high attack-complexity score (AV:L/AC:H/PR:L) indicates exploitation requires a specific, likely race-sensitive sequence of operations. Successful exploitation elevates privileges to SYSTEM, giving the attacker full control of the host, and public reporting describes deployment of a backdoor after privilege escalation. Virtually every Windows 10, Windows 11, and Windows Server (2012-2022) installation ships this driver, so the affected population is essentially the entire supported Windows installed base. The flaw is being exploited in the wild: CISA added it to the KEV on 2026-08-11, Microsoft fixed it in the August 2026 Patch Tuesday release, and reporting ties active exploitation to North Korea's Lazarus group, who paired the zero-day with fake job-offer lures.
    · Microsoft Windows Ancillary Function Driver for WinSock (afd.sys) as shipped with the Windows versions listed below · Microsoft Windows 10 1607, 1809, 21H2, 22H2 KEVmass
  • Info Leak in TCG TPM 2.0 Reference Code Enables Attestation Key Forgery
    An information-leakage flaw in the Trusted Computing Group's TPM 2.0 reference code (tracked by TCG as VRT0010 and by CERT/CC as VU#431093) allows a local attacker with elevated privileges to obtain a credential from a TPM-aware certificate authority for a falsified TPM key. It is triggered locally on systems whose TPM runs code derived from the TCG reference implementation when the attacker manipulates key-attestation flows for keys such as an Attestation Key, DevID Key, or TLS authentication key. With the fraudulently issued credential, the attacker can falsify other TPM 2.0 attestations with that key, undermining device-identity and attestation guarantees. Any deployment of the TCG TPM 2.0 reference code - including commercial TPM chips, firmware TPMs, and TPM-aware CA/attestation infrastructure - is potentially affected; the available data does not specify version ranges. No exploitation has been observed: there is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS estimates only a ~0.2% chance of exploitation in the next 30 days.
    · Trusted Computing Group (TCG) TPM 2.0 reference code (and TPM implementations derived from it)mass
  • Timing Side-Channel in TCG TPM 2.0 Reference Code RSA-OAEP Decryption
    CVE-2026-6727 is a timing side-channel vulnerability (CWE-208, tracked as TCGVRT0011) in the RSA OAEP decryption implementation of TPM 2.0 code derived from the Trusted Computing Group reference implementation. A privileged local attacker with access to the TPM command interface can measure timing differences across decryption operations to recover information sufficient to decrypt ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), import blobs, credential blobs, and session salts. Under certain conditions, the leaked information may also enable forgery of TPM 2.0 attestations, undermining trust in remote-attestation results. Any platform whose TPM 2.0 firmware is built from the affected TCG reference code is potentially affected, which spans TPM silicon from multiple vendors shipped across modern PCs, laptops, and servers; per-vendor exposure depends on whether the vulnerable code path was adopted. No public proof-of-concept or known exploitation exists (EPSS 0.2% over 30 days, not in CISA KEV).
    · Trusted Computing Group TPM 2.0 reference code (TCGVRT0011 / VU#431093) · TPM 2.0 implementations built from the TCG reference codemass

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.