Medusa, IKE RCE, MLflow: This Week's Critical Threats


Weekend Threat Roundup — Premium Edition - August 22, 2026

Week in Review

This week's threat landscape was defined by a convergence of actively exploited vulnerabilities, surging credential attacks, and ransomware milestones that underscore the sustained pressure on critical infrastructure and enterprise environments alike.

The week's most headline-grabbing disclosure came from CISA and the FBI, who confirmed that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021, according to Bleeping Computer. The scale of that figure is a stark reminder that ransomware actors continue to operate at industrial efficiency against the nation's most sensitive sectors.

On the exploitation front, CISA added two significant vulnerabilities to its Known Exploited Vulnerabilities catalog this week. A critical remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions is now being actively exploited in the wild, as reported by Bleeping Computer. Separately, threat actors are actively leveraging a critical vulnerability in the MLflow open-source AI engineering platform, with CISA warning federal agencies to remediate immediately, per Bleeping Computer. The MLflow targeting is particularly notable as it reflects threat actors pivoting toward AI/ML development infrastructure — a supply chain vector that many organizations have not yet hardened.

Credential-based attacks also reached alarming new heights. Huntress researchers documented a 155-times increase in password spraying attacks in the first half of 2026, including a single campaign that generated more than 81 million login attempts over two weeks, exploiting legacy authentication protocols and gaps in MFA policy coverage, as reported by Bleeping Computer.

On the mobile and endpoint fronts, a new Android malware strain dubbed Manic emerged, targeting users across multiple European countries with an unusual fallback exfiltration mechanism that routes stolen data through nearby infected devices, according to Bleeping Computer. Meanwhile, Citrix urged administrators to immediately patch two newly disclosed vulnerabilities in NetScaler Gateway and NetScaler ADC appliances, and a critical flaw in the widely deployed Elementor Pro WordPress plugin was disclosed, exposing sites to remote code execution via malicious file uploads.


CVE Watch

The following critical vulnerabilities were reported this week and demand immediate attention. Severity context is drawn directly from the source reporting.

  • Windows IKE Service Extensions — Critical RCE (actively exploited): CISA confirmed this week that a critical-severity remote code execution vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions component is being actively exploited in attacks. The flaw's presence in core Windows VPN and IPsec infrastructure makes it high-priority for any organization running Windows Server environments. Patch immediately. Source: Bleeping Computer.
  • MLflow Open-Source AI Platform — Critical (actively exploited): CISA warned federal agencies this week that threat actors are actively exploiting a critical vulnerability in the MLflow AI engineering platform. Organizations using MLflow for model training and experiment tracking — particularly those with internet-accessible instances — should treat this as an emergency patch priority. Source: Bleeping Computer.
  • Citrix NetScaler Gateway and NetScaler ADC — Critical (patch urgently advised): Citrix issued an urgent warning this week, urging customers to immediately patch two newly disclosed vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. Given the historical targeting of Citrix infrastructure by ransomware and nation-state actors, administrators should treat this as a weekend priority. Source: Bleeping Computer.
  • Elementor Pro WordPress Plugin — Critical RCE: A critical vulnerability in the Elementor Pro plugin could allow attackers to upload executable files and achieve remote code execution on the underlying server. With Elementor Pro installed on a very large number of WordPress sites globally, this is a high-urgency patch for any web team managing WordPress infrastructure. Source: Bleeping Computer.

Sector Spotlight: Critical Infrastructure

This week's most heavily targeted sector is critical infrastructure, and the data demands direct attention from security teams operating in energy, healthcare, transportation, water, and financial services environments.

The FBI's disclosure — reported by Bleeping Computer — that Medusa ransomware has compromised more than 500 critical infrastructure organizations since 2021 is the clearest signal yet that ransomware actors have systematically prioritized these high-stakes targets. Medusa's operational longevity — five years of sustained activity — reflects a group with the patience and resources to conduct extended campaigns, not opportunistic spray-and-pray attacks.

That threat is compounded by the active exploitation of the Windows IKE Extension RCE vulnerability, which directly affects the VPN and encrypted network tunneling infrastructure that critical infrastructure operators rely on for secure operations. A successful exploit in this context could allow adversaries to pivot deep into operational technology networks.

The 155x surge in password spraying attacks documented by Huntress is also disproportionately relevant to critical infrastructure operators, many of whom maintain legacy authentication systems and face challenges uniformly enforcing modern MFA policies across distributed operational environments. The single campaign generating 81 million login attempts in two weeks — as reported by Bleeping Computer — illustrates the sheer volume of automated pressure these organizations now face on a continuous basis.

For MSPs and managed security providers serving critical infrastructure clients, this week also surfaced timely guidance: Bleeping Computer covered analysis from Kaseya on how AI-enhanced phishing is bypassing traditional email filters, reinforcing that identity, email, and endpoint activity monitoring must be layered — no single control point is sufficient.


Your Weekly Action Plan

Based on the week's reporting, here are the concrete defensive actions your team should prioritize this weekend:

  • Patch the Windows IKE Extension vulnerability now. CISA has confirmed active exploitation of this critical RCE flaw in Windows Internet Key Exchange Service Extensions. Apply the relevant Microsoft security update to all Windows Server systems immediately — do not wait for a maintenance window. Source: Bleeping Computer.
  • Audit and patch MLflow deployments, especially internet-facing instances. If your organization uses MLflow for AI/ML development, check whether your instances are network-accessible and apply available patches. Consider temporarily restricting external access to MLflow services until remediation is confirmed. Source: Bleeping Computer.
  • Update Citrix NetScaler Gateway and ADC appliances immediately. Citrix's own advisory urges immediate action on two newly disclosed flaws. Given the history of rapid weaponization against Citrix infrastructure, assume the window between disclosure and active exploitation is short. Source: Bleeping Computer.
  • Eliminate legacy authentication and close MFA gaps across all login flows. The 155x surge in password spraying attacks specifically exploited legacy authentication protocols and login flows not covered by MFA policies. This weekend, audit your identity infrastructure: disable legacy protocols (Basic Auth, NTLM where avoidable), and ensure MFA is enforced uniformly — including on service accounts and administrative portals. Source: Bleeping Computer.
  • Update Elementor Pro on all managed WordPress sites. The critical RCE vulnerability in Elementor Pro allows arbitrary file uploads leading to server compromise. If your organization or clients run WordPress sites with Elementor Pro, push the patch this weekend and review file upload directories for any signs of suspicious content. Source: Bleeping Computer.

Looking Ahead

Several threads from this week's reporting are worth tracking closely in the days ahead.

The Medusa ransomware campaign against critical infrastructure is unlikely to slow. With 500-plus confirmed victims over five years and active FBI and CISA engagement, expect additional attribution details, possible indictments, or updated indicators of compromise to emerge in coming weeks. Organizations in sectors named in the advisory should review the published TTPs and validate their detection coverage now, before a follow-on advisory lands. Source: Bleeping Computer.

The MLflow exploitation story warrants close monitoring as a bellwether for AI infrastructure targeting. As organizations accelerate adoption of ML platforms, attackers are clearly mapping this expanded attack surface. Watch for follow-on reporting on what threat actors are doing post-exploitation — whether targeting model data, using MLflow servers as pivot points, or conducting supply chain interference.

The Manic Android malware — with its peer-to-peer exfiltration capability routing data through nearby infected devices — represents a novel evasion technique that may inspire imitation. Currently reported in European targets, watch for expansion of this campaign geographically and for analysis of the command-and-control infrastructure behind it. Source: Bleeping Computer.

Finally, with Windows 11 24H2 Home and Pro reaching end of support in approximately two months, as noted by Bleeping Computer, the clock is ticking for organizations that have not yet planned upgrade paths. As that deadline approaches, expect increased targeting of unpatched 24H2 systems — a pattern consistent with how threat actors have historically exploited end-of-support transitions.


Thanks for reading this week's Weekend Threat Roundup. Share this issue with your security team, forward it to a colleague who manages IT infrastructure, or reply with questions about anything covered above. Premium subscribers can access our full CVE tracking database and threat actor profiles in the member portal. Stay patched, stay skeptical, and we will see you next Saturday.

Subscribe to Cyber Threats Weekly