Software

Microsoft Merges Consumer and Enterprise Copilot While August Patch Tuesday Fixes 421 Vulnerabilities Including a Windows Zero-Day

Microsoft on August 13, 2026 merged its consumer and enterprise Copilot apps into a single 'Microsoft Copilot' experience, retiring several AI features that failed to gain traction. Three days later, the company's monthly Patch Tuesday shipped fixes for 421 vulnerabilities, including a Windows Ancillary Function Driver for WinSock zero-day already exploited by Lazarus-linked actors.

J
By James Park Enterprise Tech Reporter
August 18, 2026 / Updated August 19, 2026 / 6 min read

Microsoft's August 13, 2026 announcement that it was folding consumer Copilot and enterprise Copilot into a single "Microsoft Copilot" experience marked the end of the standalone Copilot Pro consumer app and the quiet retirement of several AI features that never reached scale. Three days later, the company's August 2026 Patch Tuesday shipped fixes for 421 vulnerabilities — including CVE-2026-68820, a Windows Ancillary Function Driver for WinSock zero-day already being exploited by Lazarus-linked actors.

The Copilot Consolidation

Microsoft began rolling out the unified Microsoft Copilot to mobile and web on August 13, with desktop consolidation following in the next milestone. The unified app drops "Copilot Pro" branding for consumers and replaces it with a tiered "Microsoft Copilot Free / Pro" structure, while enterprise customers retain the same SKUs and security controls under the unified brand. Microsoft is also retiring several AI features it launched over the past 18 months, including some of the Copilot Agents incubated inside Dynamics and the standalone Copilot Labs research preview.

Project Polaris and the End of GPT-4 Turbo's Default Role

Alongside the consumer-enterprise merge, Microsoft announced that Project Polaris, its internally trained coding model, will replace GPT-4 Turbo as the default engine behind GitHub Copilot starting in August 2026. The Polaris switch marks Microsoft's first full break from OpenAI as the underlying developer-software intelligence layer, and was first detailed at Microsoft Build 2026 alongside the wider MAI model family, Windows Agent Framework, and Azure Agent Mesh.

August Patch Tuesday: 421 Fixes, One Zero-Day

Microsoft's August 2026 patch release covered 421 vulnerabilities across Windows, Office, Azure, and the .NET stack. CVE-2026-68820 — a local privilege escalation in the Windows Ancillary Function Driver for WinSock that grants SYSTEM privileges — is confirmed actively exploited by Lazarus-linked actors, and Microsoft marked it "Exploitation Detected." Adobe simultaneously shipped an urgent fix for CVE-2026-71362 affecting Adobe Commerce and Magento Open Source, addressing a separate exploitation chain that had been observed in retail-skimming campaigns.

City-Forum and the 17-Month Salesforce/ServiceNow Exposure

Security firm Reco also disclosed this week that an actor it tracks as "City-Forum" spent 17 months extracting records from misconfigured Salesforce and ServiceNow portals worldwide before being detected, with thousands of enterprise customers affected. GitHub, responding to the same threat landscape, expanded Dependabot malware alerts to cover eight additional package ecosystems — including npm, PyPI, RubyGems, and Maven Central — on August 16.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.