Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

Microsoft confirms a WinSock flaw exploited

1 min read
12:09UTC

JPCERT/CC told Japanese organisations on 12 August to apply Microsoft's August updates, relaying Microsoft's confirmation that an elevation-of-privilege flaw in the Windows WinSock driver was being exploited in the wild.

TechnologyAssessed
Key takeaway

A kernel driver flaw under active exploitation gives attackers full control of a machine they already reached.

JPCERT/CC, Japan's coordination centre for computer security incidents, told Japanese organisations on 12 August to apply Microsoft's August updates, relaying Microsoft's confirmation of in-the-wild exploitation of CVE-2026-68820 1. The flaw sits in the Windows Ancillary Function Driver for WinSock, the kernel component through which Windows applications reach the network stack, and it allows elevation of privilege.

Elevation of privilege rarely opens the door. It is what an attacker uses after a phishing attachment or a stolen session has already put code on the machine with ordinary user rights, to move from that account to full control of the host. A driver running in the kernel is the shortest available route, which is why this class of flaw turns up in exploit chains rather than headlines.

The attribution chain here is worth stating plainly, because it runs three deep and is often written as one. Microsoft observed the exploitation and said so; JPCERT/CC relayed that to Japanese organisations with its own advice attached; this briefing reports the relay. Nothing in the alert is Japan's own detection, and JPCERT/CC does not claim otherwise.

Microsoft's monthly release remains the instrument the whole industry patches to, and it does not always arrive complete. In June the same cycle fixed roughly 200 flaws including six zero-days, and shipped an overdue Exchange patch sixteen days after the federal deadline for it had passed . Applying the month's updates is necessary and is not by itself an answer to what a given month left out.

Deep Analysis

In plain English

Windows has a component called the Ancillary Function Driver for WinSock that handles low-level network connections. Microsoft confirmed attackers are already exploiting a flaw in it to gain higher privileges than they should have on a compromised machine. Japan's JPCERT/CC told organisations on 12 August to install Microsoft's August security updates to close the flaw, CVE-2026-68820.

First Reported In

Update #13 · Four privileged platforms under live attack

JPCERT Coordination Center· 5 Sept 2026
Read original
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.