NINJA SIGNAL
DEFCON··MAXIMUM

TODAY

Nine CVEs hit CISA's exploited list; 121 ransomware victims in seven days.

THE THREE

  1. #1 · CVE-2026-33824

    Microsoft

    KEV

    What: This flaw in Microsoft's IKE Service lets an attacker run their own code remotely on affected Windows systems — no user interaction needed — and nearly three in four exploitation attempts succeed. Any Windows environment using IPsec or VPN tunneling is at risk of full system takeover.

    Why it moved: Actively exploited · Everyone runs this · Critical severity · 73% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Microsoft's patch for the IKE Service Extensions flaw immediately.

  2. #2 · CVE-2026-8037

    Progress

    KEV

    What: Progress LoadMaster is a common enterprise load balancer, and this flaw lets an unauthenticated attacker run any command on the appliance — effectively handing over your network edge. Exploit probability is near-certain at 99.6%, meaning automated attacks are almost certainly already scanning for this.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Patch or isolate every LoadMaster appliance from public internet access now.

  3. #3 · CVE-2026-10520

    Ivanti

    KEV

    What: Ivanti Sentry manages mobile device traffic for many organizations, and this flaw gives an unauthenticated remote attacker full root-level control — the worst possible outcome for a gateway device. Exploitation is near-certain and this has been actively exploited for months.

    Why it moved: Actively exploited · Widely deployed · Critical severity · 100% exploit odds

    Who is exploiting: Actively-exploited (CISA KEV)

    Action · Apply Ivanti's Sentry patch or take the appliance offline until patched.

TRAVERSAL

No cross-feed connection surfaced in today's graph. That's the honest reading — we don't invent one.

NUMBERS

Entities
11M
Relationships
67M
Threat actors
291
Indicators
592k
Feeds live
18
Sources total
21
ShareLinkedInX
Past editions →

Get tomorrow's brief in your inbox

07:15 UK. One email. One link. Nothing else.

Daily · one email · unsubscribe in one click · UK GDPR double opt-in.