Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
AI-summarised brief · reviewed before publication
The U.S. Cybersecurity and Infrastructure Security Agency added four critical vulnerabilities—macOS, SharePoint, VMware vCenter, and Microsoft IKE—to its Known Exploited Vulnerabilities catalog after confirming active exploitation. Apple’s flaw was used to deploy a Monero miner, SharePoint was abused following a public PoC, vCenter was targeted by a China‑linked APT deploying backdoors and reverse_ssh binaries, and Microsoft IKE was leveraged by a Chinese‑speaking actor in an AI‑driven campaign. The attacks affected 361 IP addresses in 47 countries, with Germany, the U.S., Turkey, Iran, and France most impacted.
💡 Why It Matters
- · The coordinated use of multiple high‑profile exploits demonstrates how quickly patched vulnerabilities can be weaponized, underscoring the need for rapid, cross‑vendor patch management and threat intelligence sharing.