View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CISA Flags Microsoft IKE Service Extensions Double-Free Flaw

🚨 ACTIVE EXPLOITATION

  • CISA Flags Microsoft IKE Service Extensions Double-Free Flaw CVE-2026-33824
    CISA added a Microsoft IKE double-free vulnerability to its KEV catalog.

    • Microsoft Internet Key Exchange (IKE) Service Extensions are affected.
    • CVE-2026-33824 is a double-free vulnerability that could enable remote code execution.
    • The vulnerability is being exploited in the wild.
      πŸ“Ž Coverage: nvd.nist.gov Β· πŸ‘ via CISA KEV
  • Operation CameraSwarm Compromised 14,530+ Dahua Cameras CVE-2021-33044 CVE-2021-33045
    Hunt.io observed an operator compromise more than 14,000 Dahua cameras across Ukraine and Russia.

    • Dahua IP cameras in Ukraine and Russia were the primary confirmed targets.
    • The operator compromised 14,530+ devices, including 1,923 with the persistent p2pwn/p2password backdoor.
    • Attacks used credential brute force, CVE-2021-33044/CVE-2021-33045 authentication bypasses, and Dahua P2P relay abuse.
    • The relay path reached 283 cameras by serial number without device credentials; infrastructure included 154.86.119.60:37777.
      πŸ“„ Source: labs.itresit.es Β· πŸ“Ž Coverage: hunt.io Β· πŸ‘ via r/netsec

πŸ“‹ ADVISORIES

  • Updated advisory details Medusa ransomware’s expanding victim count and tactics
    U.S. agencies say Medusa ransomware has surpassed 500 victims.

    • Medusa targets organizations opportunistically, with healthcare and public health frequently affected.
    • The ransomware-as-a-service operation steals data and encrypts networks; reported victims rose from over 300 to over 500.
    • Medusa uses access brokers, unpatched Fortra GoAnywhere and BeyondTrust flaws, and newly disclosed exploits.
    • Attackers use legitimate tools, remote monitoring software, Remote Desktop Protocol, and living-off-the-land techniques for access and lateral movement.
      πŸ“„ Source: cisa.gov Β· πŸ“Ž Coverage: cyberscoop.com Β· πŸ‘ via CyberScoop, Cyber Security News (+1)
  • πŸ“„ Source for Attackers Exploit Critical Unauthenticated SSRF in MLflow β€” github.com

  • πŸ“„ Source for Developer builds structural containment for AI-agent prompt injection β€” 404media.co

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check