Active Vulnerability Exploitation
Articles on active exploitation of newly disclosed vulnerabilities, including zero-day attacks, memory disclosure bugs, and rapid weaponization of published CVEs by threat actors.
CISA Sounds the Alarm on Actively Exploited Windows IKE Extension RCE Flaw
CISA has added CVE-2026-33824, a critical-severity remote code execution vulnerability in the Windows IKE Extension (MS-IKEE) component, to its catalog of actively exploited vulnerabilities. The flaw allows unauthorized attackers to execute code over a network by sending maliciously crafted packets to unpatched Windows systems via UDP ports 500 or 4500. CISA ordered FCEB agencies to patch within three days per Binding Operational Directive 26-04.
CISA Directs Federal Agencies to Patch Two Critical TrueConf Server Flaws
CISA has added two critical TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered U.S. Federal Civilian Executive Branch agencies to patch them within two weeks. The flaws are CVE-2026-72529 (missing authentication, remote script execution) and CVE-2026-72530 (code injection, sandbox escape for remote code execution). Kaspersky attributes exploitation to the Head Mare hacktivist group since at least July 2026.
Huntress exposes 155x password-spray surge leveraging MFA blind spots
Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign targeting Microsoft's Azure CLI from an IPv6 range controlled by LSHIY LLC, with 81 million login attempts and 78 account compromises in a two-week window. The attacks exploited MFA gaps via the legacy ROPC OAuth grant and poorly scoped Conditional Access policies.
Certighost CVE-2026-54121: How a Standard Domain User Can Turn an Enterprise CA into a Domain Controller
Certighost (CVE-2026-54121) allows a low-privileged domain user to coerce an Enterprise Certification Authority into issuing a valid authentication certificate for a Domain Controller. The patch is the easy part; the deeper privilege and trust issues linger.
Thousands of Internet-Connected Servers Backdoored by Buggy Motherboard Controllers
New research reveals thousands of servers from major manufacturers ship with vulnerable BMC firmware, enabling remote unauthorized access. CVE-2024-54085 (CVSS 10) and multiple IPMI flaws affect HPE, Dell, Lenovo, Supermicro, and others.
UK Police Database Breach: AI Cybersecurity Threats in 2026
ExfilSquad breached the UK's PNLD in July 2026, exposing 135,000 police records. Analysis of AI cybersecurity threats targeting critical law enforcement infrastructure.
AI Slop Pollutes CVE Pipeline: 54 Fake Vulnerabilities Exposed as Hallucinations
AI cybersecurity threats include 54 fake CVEs (SQLite, libraw, ESP32-audioI2S) with CVSS up to 9.8 exposed as hallucinations by JFrog. MITRE rejected all; NIST's 27,000+ backlog compounds the crisis.
How AI in Cybersecurity Uncovered Microsoft’s Record 570 Flaws
Microsoft’s July 2026 Patch Tuesday patched a record 570 vulnerabilities—many unearthed by AI scanning legacy code. This is what happens when defenders start seeing what humans missed.
The AI Supply Chain Is Broken in a Way Traditional Software Never Was
A researcher poisoned an open-weight AI model for under $100. The implications for how we trust software are far worse than any traditional supply chain attack.
AI Cybersecurity Threats 2026: When Safety Rails Block Legitimate Security Research
Strict safety guardrails on top AI models are pushing cybersecurity researchers toward unmonitored open-source alternatives. Here is how vetted programs and model restrictions impact real-world security.
Dolphin X: How a New Windows Stealer Escalates AI Cybersecurity Threats in 2026
Varonis Threat Labs discovered Dolphin X, a Windows information stealer targeting over 300 applications equipped with an AI profiler that ranks victims for maximum attacker profit.
AI Cybersecurity Threats 2026: Analyzing the Hugging Face Agentic Intrusion
An in-depth analysis of the July 2026 Hugging Face breach caused by an autonomous AI agent, examining agentic security threats, local LLM log analysis, and IAM defense practices.