ZeroHour

Source: Krebs on Security

1,198 stories

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft's September Patch Tuesday fixes a record 974 flaws, including two actively exploited Windows zero-days and critical DNS and Windows Shell bugs.

Microsoft released fixes for 974 vulnerabilities, its largest-ever monthly patch batch, bringing the 2026 total above 2,600. Two zero-day privilege elevation flaws, CVE-2026-81963 and CVE-2026-85880, are being actively exploited. Critical bugs include CVE-2026-69730, an unauthenticated DNS weakness in Windows Server 2012 onward and Windows 10 deemed likely to be exploited, and CVE-2026-69829, a CVSS 9.8 Windows Shell remote code execution flaw requiring no privileges or user interaction. Microsoft and other vendors credit AI-assisted discovery for the growing patch volumes.

Krebs on Securityupdated · 6d agofirst · 6d agoVulnerability in the wild 3 sourcesCVE-2026-81963CVE-2026-85880CVE-2026-69730+1 CVEs

FBI Probes Service Selling 153M+ Drivers Licenses

Dark web service Nexus sells scans of 153M+ US and Canadian drivers licenses, apparently siphoned from a breached identity verification company; FBI opened an inquiry.

A new dark web identity theft service called Nexus, advertised on the Exploit forum, offers scans of more than 153 million drivers licenses from the US and Canada, plus over 10 million ID cards and millions of travel and medical documents. The data appears to come from an ongoing breach at a major Louisiana-based identity verification company, with records growing by roughly 400,000 in 24 hours. Records include high-ranking US officials such as Defense Secretary Pete Hegseth, and timestamps suggest data was captured during car rentals and travel. The FBI's New Orleans field office has launched an official inquiry into the source of the images.

Krebs on Security · 13d agoData breach in the wild

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Australian Federal Police arrested two alleged TeamPCP members, a data extortion group tied to prolonged software supply chain attacks.

The Australian Federal Police arrested two unnamed suspects from Western Australia, aged 21 and 23, believed to be members of TeamPCP. The group is described as a cybercrime and data extortion syndicate blamed for the longest-running spree of software supply chain attacks, allegedly creating malicious open-source software that hit thousands of global businesses. KrebsOnSecurity had identified the 21-year-old suspect in June and had been in contact with him.

Krebs on Security · 19d agoPolicy & legal

Who’s Tracking You? Use This New Service to Find Out

KrebsOnSecurity covers DecryptAds, a free service that scrapes and correlates adtech data to reveal which entities track users across sites and apps.

KrebsOnSecurity wrote about DecryptAds, a free service that scrapes and correlates adtech data. The service makes it simple to identify which entities are responsible for ads shown on websites and data harvested by mobile apps, information that is semi-public but traditionally walled away inside large advertising platforms. No security incident is involved; the piece is an introduction to a privacy-research tool.

Krebs on Security · Aug 14, 2026Tools

Microsoft Plugs Nearly 400 Security Holes

Microsoft's August 2026 Patch Tuesday fixes 398 vulnerabilities, including one flaw already being actively exploited and two publicly disclosed before the update.

Microsoft released August 2026 Patch Tuesday updates fixing at least 398 vulnerabilities in Windows and supported software. One of the flaws is already being actively exploited, and two others were publicly detailed ahead of the patch release. The update is one of the larger monthly releases in recent memory.

Krebs on Security · Aug 11, 2026Vulnerability in the wild1