LIVE · cybersecurity feed
Live wire
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewCVE-2026-65400 · Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationOver 500 Critical Infrastructure Organizations Hit by Medusa RansomwareMedusa ransomware gang has hit over 500 organizations, CISA warns
CVE-2026-65400critical

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an

zeroday.news ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding four critical vulnerabilities that are reportedly under active exploitation. These flaws affect Apple macOS, Microsoft SharePoint, VMware vCenter Server, and Microsoft Internet Key Exchange (IKE). CISA has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating that federal civilian executive branch agencies are required to address them within a specified timeframe.

One of the vulnerabilities, identified as CVE-2026-65400 with a CVSS score of 9.8, is described as an improper authentication flaw impacting Apple macOS. This type of vulnerability typically arises when a system fails to correctly verify the identity of a user or process attempting to access a resource. An attacker exploiting such a flaw could potentially bypass authentication mechanisms, gaining unauthorized access to the affected macOS system and its resources.

Another critical flaw affects Microsoft SharePoint, a widely used web-based collaborative platform. While specific details about the SharePoint vulnerability were not provided in the summary, critical flaws in such platforms often involve remote code execution, privilege escalation, or data exfiltration. Exploitation could lead to unauthorized access to sensitive documents, compromise of the SharePoint server, or further lateral movement within an organization's network.

VMware vCenter Server is also impacted by a critical vulnerability under active exploitation. vCenter Server is a centralized management utility for VMware vSphere environments, making it a high-value target for attackers. Flaws in vCenter often involve remote code execution, which could allow an attacker to gain full control over the virtualized infrastructure, impacting numerous virtual machines and critical services.

Finally, a critical vulnerability in Microsoft Internet Key Exchange (IKE) is also being actively exploited. IKE is a protocol used to set up a security association in the IPsec protocol suite, essential for secure VPN connections. Vulnerabilities in IKE could potentially allow attackers to bypass VPN protections, intercept encrypted traffic, or gain unauthorized access to networks protected by IPsec VPNs.

For vulnerabilities of this nature, typical mitigation guidance includes applying vendor-supplied patches immediately. Organizations are also advised to implement strong authentication mechanisms, segment networks to limit the blast radius of a compromise, and monitor systems for unusual activity. Regular security audits and vulnerability scanning can help identify and address potential weaknesses before they are exploited.

The inclusion of these vulnerabilities in CISA's KEV catalog underscores the ongoing threat landscape where critical flaws in widely used enterprise and operating system software are quickly weaponized by threat actors. This highlights the persistent challenge for organizations to maintain a robust patching regimen and proactive security posture to defend against evolving cyber threats.

vulnerabilitycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

OpenAI confirms ChatGPT is down as logins and signups fail

ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]

ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

cloud

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

breach

Healthtech firm CareCloud data breach impacts 3.7 million patients

U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]