This Week In Security: It’s Patch Tuesday Again, TVs Spying, Supply Chain Worms Return, Prolonged Hack Impacts, Stolen IDs
Key Points:
- Microsoft's August 2026 Patch Tuesday included nearly 1,000 security fixes, breaking previous records and addressing two zero-day vulnerabilities actively exploited for privilege escalation on Windows systems.
- Investigations reveal LG smart TVs extensively collect user data, including video, audio, and network information, even when tracking is disabled, with security flaws enabling potential exploitation to access internal networks and record audio despite microphone muting.
- The Shai-Halud worm resurfaced in the NPM repository after 111 days, infecting packages despite existing scanning measures, raising concerns about the effectiveness of current security controls on package uploads.
- Boston Scientific continues to recover from a ransomware attack impacting company systems and operations, with ongoing efforts to restore full capacity and no public disclosure yet on data breaches.
- Adobe Commerce and Magento platforms face active exploitation of a critical vulnerability allowing remote code execution and data theft, with patches recently released following days of unmitigated attacks.
- Microsoft will block emails from unpatched on-premises Exchange servers to Exchange Online, enforcing updates that have been available since October 2025 to improve security.
- Iranian government-backed hackers use fake recruiter personas and malicious Node.js projects to deploy cross-platform remote access tools, targeting individuals in multiple countries through sophisticated spear-phishing campaigns.
- A major ID validation company, IDScan, was compromised for over a year, resulting in the theft of scans and data from 150 million US driver’s licenses, including sensitive personal information now circulating on the dark web.