๐จ ACTIVE EXPLOITATION
-
CISA says attackers are exploiting critical Windows IKE RCE flaw
Attackers are exploiting a critical Windows IKE Service Extensions flaw for remote code execution.- Affects Windows 10, Windows 11, and Windows Server systems running IKE Service Extensions.
- CVE-2026-33824 is a CVSS 9.8 double-free vulnerability enabling unauthenticated remote code execution.
- The attack targets internet-reachable IKE responders over UDP ports 500 and 4500.
- Unit 42 observed a Chinese-speaking actor manually sending reverse-shell callbacks to three IKE VPN endpoints.
๐ Source: msrc.microsoft.com ยท ๐ Coverage: blog.gridinsoft.com ยท ๐ via BleepingComputer
-
CISA flags exploited Microsoft, VMware and Apple vulnerabilities
CISA added four exploited vulnerabilities affecting Microsoft, VMware and Apple products to its KEV catalog.- Microsoft Windows IKE, SharePoint, VMware vCenter and Apple macOS Screen Sharing users are affected.
- CVE-2026-33824 enables remote unauthenticated code execution through crafted packets; CVE-2026-55040 enables SharePoint authentication bypass.
- CVE-2026-59310 allows unauthenticated vCenter directory traversal and code execution, followed by reverse SSH deployment.
- CVE-2026-65400 bypasses macOS Screen Sharing authentication, enabling root access and Monero mining.
๐ Source: cisa.gov ยท ๐ Coverage: securityweek.com ยท ๐ via SecurityWeek
๐ต๏ธ RESEARCH & DEEP DIVES
- Cursor Windows Flaw Enables Code Execution via Malicious Repository Files
A Cursor IDE flaw enabled arbitrary code execution on Windows.- Windows developers using the Cursor IDE are affected.
- CVE-2026-63093 allows a malicious repository-root git.exe to execute with the user's privileges.
- Cursor runs Git commands when opening a workspace, while Windows search can prioritize the repository directory.
- A pyproject.toml file can also trigger execution of a malicious hatch.exe binary.
๐ Source: screetsec.com ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ ADVISORIES
- BeyondTrust Windows EPM Flaws Enable Local Privilege Escalation
CVE-2026-40144CVE-2026-40145
BeyondTrust disclosed two Windows EPM flaws enabling local privilege escalation.- BeyondTrust Endpoint Privilege Management for Windows customers are affected.
- CVE-2026-40144 and CVE-2026-40145 affect Windows Deployment versions before 26.1.2.
- Attackers with local access can elevate privileges.
- One flaw can also bypass anti-tamper controls.
๐ Source: beyondtrust.com ยท ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ ADVISORIES
- ๐ Source for Microsoft Links 30+ Rotating Domains to MacSync Stealer โ rstcloud.com
๐ CVEs & KEV
- CVE-2026-75900 โ CVSS 6.1 โ Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(poi...