Microsoft’s July Patch Tuesday sets a new record for security fixes, while researchers uncover critical vulnerabilities in Dell BIOS, Windows boot loaders, and the LegacyHive registry exploit.
Key Points
- Microsoft released over 60 patches for critical Windows vulnerabilities, including fixes for BitLocker bypasses, DHCP privilege escalation, and an AI prompt injection in Edge.
- Researchers identified a Dell BIOS vulnerability allowing administrator password extraction, with passwords of 12 characters or fewer stored in plaintext.
- ESET discovered 11 Microsoft-signed boot loaders that allow attackers to bypass Secure Boot protections and execute arbitrary code.
- The LegacyHive exploit, disclosed by researcher NightmareEclipse, enables unauthorized access to the registry settings and configuration files of other Windows users.
- Fairlife Dairy suspended U.S. production operations following a ransomware attack, with no current timeline for facility restoration.
- The LAME MP3 encoder received its first update in nearly a decade, addressing long-standing stack buffer overflow and integer underflow vulnerabilities.