π¨ ACTIVE EXPLOITATION
-
CISA Flags Microsoft IKE Service Extensions Double-Free Flaw
CVE-2026-33824
CISA added a Microsoft IKE double-free vulnerability to its KEV catalog.- Microsoft Internet Key Exchange (IKE) Service Extensions are affected.
- CVE-2026-33824 is a double-free vulnerability that could enable remote code execution.
- The vulnerability is being exploited in the wild.
π Coverage: nvd.nist.gov Β· π via CISA KEV
-
Operation CameraSwarm Compromised 14,530+ Dahua Cameras
CVE-2021-33044CVE-2021-33045
Hunt.io observed an operator compromise more than 14,000 Dahua cameras across Ukraine and Russia.- Dahua IP cameras in Ukraine and Russia were the primary confirmed targets.
- The operator compromised 14,530+ devices, including 1,923 with the persistent p2pwn/p2password backdoor.
- Attacks used credential brute force, CVE-2021-33044/CVE-2021-33045 authentication bypasses, and Dahua P2P relay abuse.
- The relay path reached 283 cameras by serial number without device credentials; infrastructure included 154.86.119.60:37777.
π Source: labs.itresit.es Β· π Coverage: hunt.io Β· π via r/netsec
π ADVISORIES
-
Updated advisory details Medusa ransomwareβs expanding victim count and tactics
U.S. agencies say Medusa ransomware has surpassed 500 victims.- Medusa targets organizations opportunistically, with healthcare and public health frequently affected.
- The ransomware-as-a-service operation steals data and encrypts networks; reported victims rose from over 300 to over 500.
- Medusa uses access brokers, unpatched Fortra GoAnywhere and BeyondTrust flaws, and newly disclosed exploits.
- Attackers use legitimate tools, remote monitoring software, Remote Desktop Protocol, and living-off-the-land techniques for access and lateral movement.
π Source: cisa.gov Β· π Coverage: cyberscoop.com Β· π via CyberScoop, Cyber Security News (+1)
-
π Source for Attackers Exploit Critical Unauthenticated SSRF in MLflow β github.com
-
π Source for Developer builds structural containment for AI-agent prompt injection β 404media.co