Web_Logo
Remote Support
Security Alert: Four Critical Flaws Under Active Attack
Home » Security Alerts  »  Security Alert: Four Critical Flaws Under Active Attack

Security Alert: Four Critical Flaws Under Active Attack

Four serious security flaws are being actively exploited right now, affecting Apple macOS, Microsoft SharePoint, VMware vCenter and Windows networking components. If your business runs any of these, patching is urgent.

  • What it is: The US Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities catalogue, confirming attackers are using them in real attacks.
  • Who is affected: Organisations running macOS Screen Sharing, on-premises Microsoft SharePoint servers, VMware vCenter, or Windows systems with the IKE VPN service enabled.
  • What the risk is: The macOS flaw lets attackers bypass Screen Sharing authentication entirely and has already been used to install cryptocurrency mining malware. The SharePoint and vCenter flaws have both been exploited to gain remote access and plant backdoors, including by a suspected state-linked group. The Windows IKE flaw allows remote code execution with no user interaction.
  • What action is needed: Apply the latest vendor patches for macOS, SharePoint, vCenter and Windows as soon as possible. Do not wait for a routine maintenance window.

We recommend businesses treat this as a priority patch cycle, particularly if any of the affected systems are internet-facing.