Microsoft's August update closes 398 flaws, one of them a Windows kernel driver bug already under active exploitation in the wild before Tuesday's patch. The driver handles network socket operations, the same layer that lets an attacker pivot from local access to kernel-level control once the initial foothold is in. Microsoft's advisory credits its own detection telemetry for catching the exploitation. What it does not say is how long the flaw sat live before that telemetry caught it, because Microsoft has not published one.
The same week, Dark Reading is tracking water utility intrusions spreading across a twelfth state, still running through internet-exposed programmable logic controllers that CISA told operators to take offline in April. One incident got a same-day patch and a CVE number. The other has been public knowledge for sixteen weeks and the controllers are still reachable. The difference is not the severity of the bug. It is which victim has a patch Tuesday.