NINJA SIGNAL
DEFCON··MAXIMUM

TODAY

Perfect-10 Oracle/Apache flaw hits KEV; 113 ransomware victims this week.

THE THREE

  1. #1 · CVE-2026-21962

    Apache

    KEV

    What: If you run Oracle WebLogic or Apache HTTP Server with the WebLogic Proxy Plug-in (versions 12.2.1.4.0 or 14.1.1), this CVSS 10.0 flaw — added to CISA's KEV list just yesterday — lets attackers fully compromise your web infrastructure with no authentication. Exploitation is already confirmed in the wild.

    Why it moved: Actively exploited · KEV-listed this week · Everyone runs this · Critical severity · New this week

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Immediately isolate or patch Oracle WebLogic Proxy Plug-in on all affected servers.

  2. #2 · CVE-2026-33824

    Windows

    KEV

    What: This Windows IKE Extension flaw lets an unauthenticated attacker run arbitrary code over the network — meaning any Windows system using IPsec/IKE is potentially exposed to full takeover without any user interaction. With a 73% exploit probability and KEV-listed this week, active attacks are underway.

    Why it moved: Actively exploited · Everyone runs this · Critical severity · 73% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Microsoft's patch for CVE-2026-33824 on all Windows systems immediately.

  3. #3 · CVE-2026-8037

    Progress

    KEV

    What: Progress LoadMaster — a widely used load balancer — has a command injection flaw that unauthenticated attackers are exploiting with near-certain success (99.6% EPSS), letting them run any command on the appliance and pivot into your network. This is a perimeter device, so compromise means attackers are inside.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply the Progress LoadMaster patch or take the appliance offline until patched.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
11M
Relationships
67M
Threat actors
289
Indicators
575k
Feeds live
0
Sources total
21
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.