AI Security AI安全 2d ago Updated 2d ago 更新于 2天前 45

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation macOS、SharePoint、vCenter和Microsoft IKE关键漏洞正遭活跃利用

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, all with CVSS scores of 9.1 or higher, indicating severe risk to enterprise infrastructure A China-nexus APT exploited the VMware vCenter path traversal flaw (CVE-2026-59310) to deploy backdoors, reverse_ssh binaries, and Babuk-derived ransomware across 361 victims in 47 countries A Chinese-speaking threat actor combined AI-enabled autonomous hacking using DeepSeek with manual exploitation of the Microsoft I CISA将四个关键漏洞加入已知利用目录,涉及Apple macOS、Microsoft SharePoint、VMware vCenter和Microsoft IKE服务,均处于活跃利用状态 中国关联APT利用VMware vCenter路径遍历漏洞部署后门及Babuk勒索软件,361个受害IP遍布47个国家 出现AI辅助自主黑客新趋势:威胁行为体结合DeepSeek进行自动化攻击,同时手动利用已知漏洞 联邦民用行政分支机构需在2026年8月21日前完成系统修补,遵循BOD 26-04指南

72
Hot 热度
62
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, all with CVSS scores of 9.1 or higher, indicating severe risk to enterprise infrastructure
  • A China-nexus APT exploited the VMware vCenter path traversal flaw (CVE-2026-59310) to deploy backdoors, reverse_ssh binaries, and Babuk-derived ransomware across 361 victims in 47 countries
  • A Chinese-speaking threat actor combined AI-enabled autonomous hacking using DeepSeek with manual exploitation of the Microsoft IKE vulnerability (CVE-2026-33824), marking a notable convergence of generative AI and traditional exploit campaigns
  • Federal Civilian Executive Branch agencies must patch vulnerable systems by August 21, 2026, per BOD 26-04 guidelines

Why It Matters

This article highlights an escalating trend where nation-state actors are integrating generative AI tools like DeepSeek into their offensive operations, potentially lowering the barrier to sophisticated cyberattacks and increasing the velocity of exploitation campaigns. For AI practitioners and security professionals, it underscores the urgent need to monitor how AI capabilities are being weaponized alongside traditional vulnerability exploitation, and to prioritize patching critical infrastructure vulnerabilities that are actively being exploited in the wild.

Technical Details

  • CVE-2026-65400 (CVSS 9.8): Improper authentication flaw in Apple macOS allowing network-based attackers to authenticate to Screen Sharing without valid credentials; exploited to deliver Monero cryptocurrency miners
  • CVE-2026-55040 (CVSS 9.1): Weak authentication vulnerability in Microsoft SharePoint enabling unauthorized attackers to bypass security features over a network; PoC code released and subsequently exploited by unknown actors
  • CVE-2026-59310 (CVSS 9.8): Path traversal vulnerability in Broadcom VMware vCenter allowing arbitrary code execution with network access; exploited by a suspected China-nexus APT to deploy persistent backdoors and ransomware
  • CVE-2026-33824 (CVSS 9.8): Double free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions enabling remote code execution; exploited by a Chinese-speaking threat actor using a hybrid AI-autonomous and manual attack approach
  • Attack impact spans 361 unique victim IPs across 47 countries, with top concentrations in Germany (55), the U.S. (41), Turkey (38), Iran (26), and France (25)

Industry Insight

  • Organizations should treat AI-augmented threat campaigns as a new operational reality; the use of DeepSeek for autonomous hacking suggests that threat actors are rapidly adopting generative AI for reconnaissance, exploit generation, and attack orchestration, necessitating updated detection strategies that account for AI-driven behavior patterns
  • The active exploitation of critical infrastructure vulnerabilities in VMware vCenter and Microsoft IKE services demands immediate patching prioritization, especially for Federal Civilian Executive Branch agencies bound by the August 21, 2026 deadline under BOD 26-04
  • The convergence of nation-state APT activity with accessible AI tools signals a democratization of sophisticated attack capabilities; security teams should invest in AI-powered threat detection and response systems to counter similarly augmented adversary operations

TL;DR

  • CISA将四个关键漏洞加入已知利用目录,涉及Apple macOS、Microsoft SharePoint、VMware vCenter和Microsoft IKE服务,均处于活跃利用状态
  • 中国关联APT利用VMware vCenter路径遍历漏洞部署后门及Babuk勒索软件,361个受害IP遍布47个国家
  • 出现AI辅助自主黑客新趋势:威胁行为体结合DeepSeek进行自动化攻击,同时手动利用已知漏洞
  • 联邦民用行政分支机构需在2026年8月21日前完成系统修补,遵循BOD 26-04指南

为什么值得看

本文揭示了国家级威胁行为体正在将AI工具(DeepSeek)整合到网络攻击链中,标志着自主黑客活动进入新阶段。同时,企业核心基础设施(虚拟化、协作平台、操作系统)的多个关键漏洞被同时利用,对组织的安全响应能力提出严峻考验。

技术解析

  • CVE-2026-65400(CVSS 9.8):Apple macOS屏幕共享认证绕过漏洞,允许网络攻击者无需有效凭据即可认证访问,已被用于投递Monero加密货币挖矿程序。
  • CVE-2026-55040(CVSS 9.1):Microsoft SharePoint弱认证漏洞,攻击者可通过网络绕过安全特性,PoC代码发布后已被未知行为体利用。
  • CVE-2026-59310(CVSS 9.8):Broadcom VMware vCenter路径遍历漏洞,具有网络访问权限的攻击者可执行任意代码,被中国关联APT用于部署后门、reverse_ssh二进制文件及Babuk衍生勒索软件。
  • CVE-2026-33824(CVSS 9.8):Microsoft IKE服务扩展双重释放漏洞,允许未经授权的攻击者通过网络执行代码,已被中国语言威胁行为体利用,结合DeepSeek开展AI辅助自主黑客行动。
  • 攻击影响范围:361个唯一受害IP地址,覆盖47个国家,主要集中在德国(55)、美国(41)、土耳其(38)、伊朗(26)和法国(25)。

行业启示

  • AI赋能网络攻击已成现实:威胁行为体开始将DeepSeek等AI模型整合到攻击链中,实现自动化漏洞利用与手动操作相结合,安全团队需重新评估AI双刃剑风险。
  • 企业核心基础设施成为重点目标:虚拟化平台(vCenter)、协作系统(SharePoint)和操作系统(macOS)的漏洞被国家级APT积极利用,组织应优先修补关键基础设施漏洞。
  • 合规时效性要求紧迫:联邦机构需在2026年8月21日前完成修补,企业应参考BOD 26-04指南,建立快速漏洞响应机制,避免成为攻击者目标。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究