Generated · Archived snapshot 12 findings · 2 CVEs
On this page

Exploitation Report

Executive Summary

CISA has added multiple critical vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming active exploitation of flaws in Apple macOS (CVE-2026-65400), Microsoft Windows IKE Extension, Ray distributed computing framework, and Windows Task Host. These vulnerabilities enable remote code execution, improper authentication bypass, and browser-based code execution, with ransomware gangs specifically leveraging the Windows Task Host flaw. The GitLab zero-click vulnerability (CVE-2026-19478) presents significant mitigation challenges due to limited technical disclosure.

Threat actor activity remains diverse and sophisticated. The Clop ransomware gang has deployed a custom Java web shell targeting PTC Windchill and FlexPLM servers to decrypt credentials and exfiltrate engineering data. The Medusa ransomware operation has compromised over 500 critical infrastructure organizations since June 2021. A China-linked operator demonstrated near-autonomous AI-driven attacks against government agencies in the APAC region, while the TWINLOOT framework operates entirely within Microsoft's cloud ecosystem abusing SharePoint and Teams for command and control. The Ransom Busters affiliate has adopted a novel extortion model posing as an incident recovery service.

Supply chain and infrastructure compromise campaigns are escalating. The StopAndProtect operation leverages nearly 2,000 hacked WordPress sites as a distributed malware delivery platform. A persistent attacker has scraped Salesforce and ServiceNow portals across multiple industries since 2025 using infrastructure tied to the "City Forum" campaign. Typosquatted RubyGems packages (StubMaker campaign) target developers with credential and cryptocurrency wallet stealers, while MLflow SSRF flaws are being actively exploited to harvest cloud credentials and secrets from AI/ML workloads.

Active Exploitation Details

CriticalActive exploitationPatchCVE-2026-65400#

  • Description: An improper authentication vulnerability in Apple macOS that could allow an attacker to bypass authentication mechanisms and gain unauthorized access to affected systems.
  • Impact: Attackers can achieve unauthorized system access, potentially leading to full device compromise, data theft, and lateral movement within enterprise environments.
  • Status: Actively exploited in the wild; added to CISA KEV catalog on August 12, 2026. Patch availability not specified in source.

CriticalActive exploitationPatchCVE-2026-65400#

  • Description: A critical-severity remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions component that allows unauthenticated attackers to execute arbitrary code.
  • Impact: Remote code execution with system-level privileges, enabling complete system compromise without user interaction.
  • Status: Actively exploited in attacks; CISA has issued warning. Patch availability not specified in source.

CriticalActive exploitationPatch#

  • Description: A critical flaw in Ray, an open-source Python-native distributed computing framework for AI/ML workloads, that can trigger browser-based remote code execution.
  • Impact: Attackers can achieve remote code execution through browser vectors, compromising AI/ML infrastructure and potentially accessing sensitive training data, models, and cloud credentials.
  • Status: Actively exploited; added to CISA KEV catalog on August 11, 2026.

HighActive exploitationPatch#

  • Description: A high-severity vulnerability in Windows Task Host that was previously flagged as actively exploited in April 2026.
  • Impact: Ransomware gangs are actively exploiting this flaw to gain initial access and deploy ransomware payloads across victim networks.
  • Status: Confirmed exploited by ransomware gangs; CISA advisory issued.

CriticalPotentialInvestigateCVE-2026-19478#

  • Description: A critical zero-click flaw in self-managed GitLab instances that poses significant mitigation challenges due to lack of technical details in public disclosures.
  • Impact: Potential zero-click compromise of GitLab servers, enabling source code theft, supply chain injection, and CI/CD pipeline manipulation.
  • Status: Critical vulnerability with exploitation potential; limited technical details hinder detection and mitigation.

CriticalActive exploitationPatch#

  • Description: A critical security flaw in PTC Windchill and FlexPLM Product Lifecycle Management servers that enables deployment of a custom JavaServer Pages web shell.
  • Impact: Attackers deploy a fully equipped extortion platform capable of decrypting credentials, mapping sensitive vault data, enumerating file repositories, and exfiltrating engineering intellectual property.
  • Status: Actively exploited by Clop ransomware gang; custom web shell deployed post-exploitation.

CriticalActive exploitationPatch#

  • Description: A critical Server-Side Request Forgery vulnerability in MLflow, an open-source AI platform, being exploited to steal cloud credentials and secrets.
  • Impact: Attackers can access internal cloud metadata services, extract credentials, API keys, and secrets from MLflow deployments, compromising entire ML pipelines and associated cloud infrastructure.
  • Status: Malicious scanning and exploitation observed by watchTowr and VulnCheck.

HighPotentialInvestigate#

  • Description: Three vulnerabilities in Microsoft Copilot Personal (collectively named CoSnitch) involving an undocumented URL parameter that enables single-click data exfiltration from connected apps.
  • Impact: A single click on a crafted link silently pulls data from connected applications and information available in the victim's Copilot session.
  • Status: Disclosed by Varonis Threat Labs; exploitation status not confirmed in wild.

CriticalActive exploitationPatch#

  • Description: A critical vulnerability in FUXA, an open-source web-based SCADA/HMI software for operational technology and industrial automation.
  • Impact: Potential compromise of industrial control systems, enabling manipulation of OT environments and critical infrastructure.
  • Status: Malicious scanning and exploitation efforts observed alongside MLflow attacks.

HighActive exploitationInvestigate#

  • Description: A global cybercrime operation abusing nearly 2,000 hacked WordPress websites as infrastructure for malware distribution, command and control, and data staging.
  • Impact: Large-scale malware dissemination, host compromise, credential theft, and persistent infrastructure for criminal operations using a toolkit of criminal software.
  • Status: Active operation with thousands of compromised sites serving as infrastructure.

HighActive exploitationInvestigate#

  • Description: A typosquatting campaign publishing 16 malicious RubyGems packages that deploy a Windows-based information stealer targeting browser credentials and cryptocurrency wallets.
  • Impact: Developer credential theft, cryptocurrency wallet drainage, and potential supply chain compromise through compromised development environments.
  • Status: Active campaign discovered August 15, 2026; packages published to RubyGems registry.

MediumObservedMonitor#

  • Description: An authorization flaw in an order-tracking plug-in that exposed customer PII including names, emails, shipping addresses, phone numbers, and purchase details.
  • Impact: Data exposure of approximately 39,798 hardware wallet customers; not confirmed as actively exploited but data was accessible.
  • Status: Disclosed by vendor; affected customers notified.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities