Microsoft Patch Tuesday: 1,000 Fixes, Zero-Days Exploit TVs Spying
Microsoft's latest Patch Tuesday addresses nearly 1,000 vulnerabilities, including two zero-days. Meanwhile, investigations reveal LG smart TVs may be excessively collecting user data, and supply chain attacks resurface.

Microsoft's monthly Patch Tuesday for August 2026 arrived with a staggering number of security fixes, nearly 1,000 in total, according to a report by Brian Krebs of KrebsOnSecurity. This marks a significant increase, raising concerns about the ongoing complexity of securing Microsoft products. Among the critical updates are two zero-day vulnerabilities that were actively being exploited in the wild. These flaws allow for privilege escalation on Windows systems, a dangerous capability that can transform lesser exploits into full administrative access, paving the way for ransomware deployment and persistent threats.
Beyond the zero-days, the patch set also includes a vulnerability rated CVSS 9.8, extremely close to a perfect score. This flaw permits remote code execution on the Windows shell without user interaction or authentication. Additionally, a remotely exploitable DNS bug, present since Windows Server 2012 and Windows 10, is likely to see widespread exploitation soon. With over a hundred other bugs categorized as "Critical," the sheer volume of patches presents a significant challenge for organizations. The effectiveness of applying these immediate fixes hinges on whether the patches introduce new issues or conflicts, a common concern following large update rollouts.
Smart TV Data Collection Raises Privacy Concerns
Investigations into the data collection practices of smart devices continue, with a recent deep dive by Gamers Nexus focusing on LG televisions and monitors. Their multi-hour analysis suggests that smart TVs, often more beneficial to advertisers than consumers, harvest user data extensively. Reports indicate that LG devices collect significant amounts of data, even when tracking features are ostensibly turned off. Executives have reportedly stated that LG "owns the glass" and "owns the living room," aiming to correlate devices, occupants, and viewing habits to serve targeted ads across TVs and mobile devices in the same vicinity. The telemetry data captured includes application usage, screen content (even from HDMI inputs), and viewing fingerprints sent to LG servers and advertising partners. When voice control is enabled, the TV also records and analyzes audio. Furthermore, LG TVs scan local and nearby Wi-Fi networks, collecting device information like hostnames and MAC addresses, which can be used for precise geolocation.
While the invasive ad technology might be optional if users decline the end-user license agreement, the underlying infrastructure appears to be riddled with security flaws. A smart TV, essentially a computer running a flavor of Android or Linux, is susceptible to the same vulnerabilities as any other device. Gamers Nexus demonstrated that an exploited LG TV could grant local root access, enabling it to record audio from attached devices, even if the primary microphone is muted. In some models, muting the microphone does not disable it but merely reduces its gain, allowing audio recovery with amplification. This intersection of surveillance technology and advertising practices leaves open questions about LG's response to hardening device security or whether a market will emerge for non-smart, privacy-focused televisions.
In a separate supply chain incident, the Shai-Halud NPM Worm has reappeared in the NPM repository after a 111-day absence. This worm, which previously installed backdoors, stole cryptocurrency, and harvested credentials in Spring 2026, was detected in four additional packages uploaded on September 7, 2026. Despite NPM's claims of scanning all uploaded packages, the original code's re-emergence raises questions about the effectiveness of current security measures against known threats.
The ongoing cyberattack against medical device manufacturer Boston Scientific continues to have financial repercussions. The company reported to the SEC that the apparent ransomware attack is expected to impact earnings. While customer data compromise details remain undisclosed, the breach caused system outages. Boston Scientific has indicated that shipping operations are nearing full capacity and sterilization facilities are operational, though a full recovery timeline has not been provided.
Finally, Adobe has issued a security bulletin for its Adobe Commerce and Magento platforms, warning of active exploitation targeting CVE-2026-75650. This flaw in the template engine affects tens of thousands of e-commerce sites, often used to steal payment data or distribute malware. The vulnerability allows for the injection of PHP code via custom styles in a query, which is then executed when Magento generates failure emails. Attackers then deploy a Rust-based control binary to monitor stores and collect payment information. Patches are now available, but the vulnerability was exploited in the wild for several days before Adobe released official advisories.
