All issues
Tech & Security Intelligence Issue 013 · 17 Aug 2026

The Weekly
Brief

Another vast Patch Tuesday from Microsoft — and one flaw in it was already being used. Our spy agency says foreign states are after Kiwi companies' ideas, Copilot changes address on Monday, and the NCSC wants you to look at your suppliers.

Paul, Director of Node-Red
Curated by Paul
Editor · Node-Red

4 stories · 6 min read

In this issue

01 Threat Alert

One of the 400 flaws Microsoft fixed this month was already being used

On 11 August Microsoft shipped another enormous security update — around 400 flaws across Windows, Office and the services behind them, 42 of them rated critical. (Counts vary between 398 and 421 depending on whose tally you read, because vendors differ on whether to include third-party components.) It continues a run of unusually heavy months; July's release was larger still. Buried in the pile were three zero-days — flaws that were public, or being exploited, before a fix existed. Two had merely been disclosed. The third had already been put to work.

That one is CVE-2026-68820, a use-after-free bug in the Windows Ancillary Function Driver for WinSock (afd.sys) — an unglamorous kernel driver that sits underneath every network connection a Windows machine makes. Rated CVSS 7.0, it needs local access, so on its own it doesn't get an attacker in; what it does is let someone who is already running as an ordinary user promote themselves to SYSTEM. Check Point traced its use to Lazarus, the North Korean state-linked group, which used it during intrusions at defence firms to install a new build of FudModule — a rootkit that runs in the Windows kernel itself, where most security tooling can't easily see it. It is the fourth zero-day in this same driver in three years.

02 New Zealand

The NZSIS says foreign states are targeting New Zealand companies for what they know

On 13 August the New Zealand Security Intelligence Service published its annual Security Threat Environment report — the one public document each year in which the country's spy agency says plainly what it is worried about. The 2026 edition names four: espionage, foreign interference, insider threats and violent extremism. What's changed is who it says is in the firing line.

It is no longer just government. The NZSIS assesses that foreign states and their proxies are targeting New Zealand companies, universities and research institutions, and that the objective is usually intellectual property, technology and other non-public information — anything that shortens the road to an industrial or military capability. Firms and researchers working on dual-use technology, such as AI and commercial drones, are singled out as particularly exposed, often approached through academic exchanges, conferences and flattering recruitment offers rather than anything that looks like spying. Alongside that, the agency reports a rise in insider cases — staff who cause harm deliberately, under outside influence, or simply by having access they shouldn't — and notes that the NCSC has seen espionage-motivated cyber activity climb steadily for three years. The report expects espionage against New Zealand to increase over the next twelve months.

03 Microsoft 365

Copilot moves to a new web address on Monday — check it isn't blocked before staff notice

From 18 August Microsoft begins changing the Copilot app across web, desktop and mobile. Most of it is cosmetic — a simplified name and icon, and clearer labelling so people can tell at a glance whether they are using their work account or their personal one, including a green shield badge on work sign-ins. The part worth an administrator's attention is the address: the web app moves from m365.cloud.microsoft to copilot.cloud.microsoft.

Users are redirected automatically — unless the new address is blocked on your network. Microsoft's advice to partners is explicit: confirm copilot.cloud.microsoft isn't caught by an existing proxy, firewall or web-filtering rule, and where appropriate allow *.cloud.microsoft as a whole. An early preview of the updated Windows and Mac desktop app also lands on 18 August, with broad deployment starting mid-September. Security, compliance and governance controls are unchanged.

04 Supply Chain

The NCSC's message on suppliers: their breach is still your breach

On 4 August the NCSC published guidance for organisations that use third parties to collect and store information — written, it says, in the wake of several incidents where the breach happened at a supplier rather than at the organisation whose customers were affected. Its central point is unfashionably simple: managing a supplier is an ongoing process, not a decision you make once at signing.

The legal position underneath it is worth stating plainly, because a lot of businesses have it backwards. Under the Privacy Act 2020 your organisation is required to have reasonable security safeguards over the personal information you hold — and handing that information to a supplier does not hand over the obligation with it. The NCSC's guidance sets out questions to ask when choosing a provider and, more usefully, how to keep asking them afterwards. It also makes a point that cuts against a common assumption: attackers rarely need anything sophisticated to get into a poorly protected system, and how attractive your data is has very little to do with how big your company is.

Tip of the week

Prove August's updates actually landed — don't just trust the setting

"Automatic updates are on" is a setting, not an outcome. With a Windows flaw from 11 August already being exploited, this week is a good week to check the outcome instead — and it takes about five minutes per machine. On a Windows PC, open Settings → Windows Update → Update history and look for a 2026-08 entry. If the newest thing there is from July, that device has been sitting on a pending update for a week, and a device that is waiting to restart is not a device that is patched. The usual culprits are predictable: the laptop that lives in a car and rarely stays on long enough to finish, the machine nobody logs off so the restart never happens, and the PC in the corner running one old application that everyone is scared to touch. Walk around and check those three first — they'll account for most of what you find. Anything that genuinely can't be updated needs a different answer than hope: get it off the general network, or off the network entirely. And extend the same question beyond Windows this month, because it's the same failure everywhere — phones, the browser, and the firewall or router, which almost never updates itself and almost never gets checked. If we manage your fleet, we've pushed August's updates and are verifying installs device by device this week; ask and we'll send you the list, including anything still refusing to take it.

Node-Red

Want all of this handled for you?

We keep an eye on the threats, the updates and the fine print so you don't have to. Book a free, no-obligation IT checkup.

Book your free IT checkup