Spooky season is in full swing, and this extends to Microsoft's October Patch Tuesday with security updates for a frightful 175 Microsoft vulnerabilities , plus an additional 21 non-Microsoft CVEs. And even scarier than the sheer number of bugs: three are listed as under attack, with three others publicly known, and 17 deemed critical security holes.

Let's start with the flaws that attackers already found and exploited before Redmond pushed patches.

Publicly known, but not under attack…yet

Three other bugs are listed as publicly known, which means that attackers are likely already scanning for vulnerable software. These include:

In addition to the critical bug in some AMD EPYC processors, the other 16 critical-severity flaws in this month's Patch Tuesday can lead to elevation of privil

See Full Page