NINJA SIGNAL
DEFCON··MAXIMUM

TODAY

Windows IKE and macOS Screen Sharing under active attack — patch now.

THE THREE

  1. #1 · CVE-2026-33824

    Windows

    KEV

    What: This Windows flaw lets an unauthenticated attacker run their own code on your machine over the network — no login required — and was added to CISA's known-exploited list just yesterday, meaning real attacks are already happening. Any Windows system reachable on the network is at risk of full takeover.

    Why it moved: Actively exploited · KEV-listed this week · Everyone runs this · Critical severity · 56% exploit odds · New this week

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Microsoft's patch for CVE-2026-33824 to all Windows systems immediately.

  2. #2 · CVE-2026-8037

    Progress

    KEV

    What: Progress LoadMaster load balancers have a command injection flaw with a 99% exploit probability, meaning attackers can run any command on the appliance without logging in — handing them a foothold into your network traffic and backend systems. If you use LoadMaster for application delivery, assume it is a target right now.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 99% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Update Progress LoadMaster to the vendor-patched version without delay.

  3. #3 · CVE-2026-34486

    Apache

    KEV

    What: Apache Tomcat's encryption protection can be bypassed, and this flaw chains with a previously known vulnerability (CVE-2025-24813) to make exploitation easier — 83% exploit odds means attackers are actively weaponizing this combination. Any org running Tomcat for web apps could face data exposure or remote code execution.

    Why it moved: Actively exploited · Everyone runs this · 83% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Patch Apache Tomcat and verify EncryptInterceptor is correctly configured post-update.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
11M
Relationships
66M
Threat actors
356
Indicators
564k
Feeds live
0
Sources total
21
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.