Today’s Field Note
CISA added a critical Windows IKE Service Extensions RCE to the KEV list, and it is being exploited now, which means the IPsec stack you assumed was boring is a live entry point. Meanwhile Clop is running true to form: ReliaQuest and BleepingComputer both confirm a purpose-built JSP web shell for PTC Windchill and FlexPLM that decrypts stored credentials, maps vaults, and stages files for extortion. On the AI/ML side, watchTowr and VulnCheck report active scanning and exploitation of an MLflow SSRF flaw being used to lift cloud credentials, so your data-science sandbox is now a cloud-takeover vector. None of these are theoretical. All three have attackers on the keyboard today.
Today’s Action
- Patch the Windows IKE Extensions RCE across all IPsec/VPN endpoints per CISA KEV timelines; if you cannot patch immediately, restrict IKE (UDP 500/4500) exposure at the edge.
- Hunt PTC Windchill and FlexPLM servers for unexpected JSP files, then rotate every credential those systems could decrypt or reach.
- Update MLflow and place it behind authentication; audit outbound requests from MLflow hosts and rotate any cloud keys or instance-metadata-derived credentials it could touch.
- Push Chrome (two critical buffer overflows) and Apple iOS/iPadOS/macOS Tahoe (image-processing RCE) updates to managed fleets now, not next cycle.
- If you run self-managed GitLab, track CVE-2026-19478; detection is hard, so prioritize upgrading over hoping to spot the zero-click.
Resources
Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.
- CVE-2026-19478: NVD advisory · Search Sigma for detection rules
The stack you called boring is the one they logged into first.
Related
- OpenAI’s Own Models Broke Out of Their Sandbox and Hacked Hugging Face
- SIM Cards, Gym Bots, and a Polish Turbine That Stopped Turning
- An AI Test Model Broke Into Hugging Face and Nobody Noticed for a Weekend
More: Issues · Field Notes · RTFM
Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.