Breaking
Is your home protected against EV fire? Here’s what Malaysian insurers have to sayNusantara Battery: First look at new power pack co-developed by Malaysia, IndonesiaPortugal enforces ban on face coverings in public placesPax Silica hub in New Clark City to get governing framework by NovemberMaking better robots depends on better data capture, Chinese firm 51World saysChina Evergrande liquidators take regulator to court over HK$1 billion PwC dealMicrosoft fixes Windows Defender crash bug in new signature updateMicrosoft warns of active attacks exploiting critical Windows IKE Extension flawIndonesia targets geothermal non-tax revenue at Rp2.6 trillion in 2026Pertamina diverts 16 tankers to Flores after quake knocks out Reo terminalValley of flowers struggles to bloom under Himalayan development surgeCOE premiums rise again as supply falls shortRelativity Networks raises $22 million to bring a faster kind of fiber to data centersAmazon to expand drone deliveries to suburban Chicago, AtlantaIndonesian trade ministry’s business matching programme raises Rp5.95 trillion in dealsSime Darby Property buys Wisma Unirazak for RM160 millionPerdana Petroleum swings to RM8.3 million 1H26 loss as workbarge weakness bitesOptimax 1H26 PAT Edges Down 6.3% To RM7.5 Million While Quarterly Revenue Hits Record HighCHGP and UCSI form education hub in Melaka waterfrontMore graduates, uncertain futures: India’s youth question what a university degree can deliverIs your home protected against EV fire? Here’s what Malaysian insurers have to sayNusantara Battery: First look at new power pack co-developed by Malaysia, IndonesiaPortugal enforces ban on face coverings in public placesPax Silica hub in New Clark City to get governing framework by NovemberMaking better robots depends on better data capture, Chinese firm 51World saysChina Evergrande liquidators take regulator to court over HK$1 billion PwC dealMicrosoft fixes Windows Defender crash bug in new signature updateMicrosoft warns of active attacks exploiting critical Windows IKE Extension flawIndonesia targets geothermal non-tax revenue at Rp2.6 trillion in 2026Pertamina diverts 16 tankers to Flores after quake knocks out Reo terminalValley of flowers struggles to bloom under Himalayan development surgeCOE premiums rise again as supply falls shortRelativity Networks raises $22 million to bring a faster kind of fiber to data centersAmazon to expand drone deliveries to suburban Chicago, AtlantaIndonesian trade ministry’s business matching programme raises Rp5.95 trillion in dealsSime Darby Property buys Wisma Unirazak for RM160 millionPerdana Petroleum swings to RM8.3 million 1H26 loss as workbarge weakness bitesOptimax 1H26 PAT Edges Down 6.3% To RM7.5 Million While Quarterly Revenue Hits Record HighCHGP and UCSI form education hub in Melaka waterfrontMore graduates, uncertain futures: India’s youth question what a university degree can deliver
Economy

Microsoft warns of active attacks exploiting critical Windows IKE Extension flaw

Hackers are actively exploiting a critical-severity remote code execution (RCE) flaw in Microsoft’s Windows Internet Key Exchange (IKE) Service Extensions, the company said in its April 2026 Patch Tuesday advisory.

Source: BleepingComputer · August 19, 2026 at 12:31 PM · AI-assisted report

Single-source

KUALA LUMPUR, 19 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

CRITICAL WINDOWS IKE FLAW NOW UNDER ACTIVE ATTACK, MALAYSIAN AGENCIES URGED TO ACT

Market Impact

KUALA LUMPUR — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical remote code execution (RCE) vulnerability in Microsoft’s Windows Internet Key Exchange (IKE) Service Extensions is being actively exploited by hackers. The flaw, tracked as CVE-2026-33824, affects all supported versions of Windows 10, Windows 11, and Windows Server, allowing unauthenticated attackers to execute arbitrary code by sending maliciously crafted packets via UDP ports 500 or 4500.

The vulnerability stems from a double-free error in the IKE Extension, which Microsoft disclosed and patched during the April 2026 Patch Tuesday release. While Microsoft has not yet updated its advisory to confirm in-the-wild exploitation, CISA has added the flaw to its Catalog of Known Exploited Vulnerabilities and issued a Binding Operational Directive (BOD 26-04), mandating that U.S. federal agencies remediate the issue within three days.

CISA has urged all organizations, including Malaysian entities, to prioritize patching to mitigate ongoing attacks.

The IKE Service Extensions, also known as MS-IKEE, enhance the Internet Key Exchange Protocol v2 (IKEv2) with features such as cryptographically generated address (CGA) authentication, denial-of-service protection, and improved interoperability with non-IPsec-capable peers. Exploitation requires IKEv2 to be enabled, making systems with this protocol particularly vulnerable.

Microsoft has advised security teams unable to apply the patch immediately to block inbound traffic on UDP ports 500 and 4500 or restrict access to known peer addresses via firewall rules.

CISA’s warning follows a broader trend of escalating cyber threats targeting Microsoft products. Since November 2021, the agency has catalogued 385 actively exploited vulnerabilities in Microsoft software, 112 of which have been leveraged in ransomware attacks. Recent incidents include the exploitation of a high-severity Windows Task Host vulnerability in ransomware operations and the abuse of a Microsoft SharePoint RCE flaw confirmed in early July.

These trends underscore the persistent risk posed by unpatched systems, particularly as attackers increasingly rely on valid credentials to bypass traditional defenses.

For Malaysian organizations, the immediate priority is to assess exposure to CVE-2026-33824 and apply Microsoft’s security update. Systems running Windows 10/11 or Windows Server with IKEv2 enabled are at highest risk. The Malaysian Cyber Security Agency (NACSA) and CyberSecurity Malaysia are expected to issue local advisories in line with CISA’s directive. Industry analysts note that while signature-based prevention methods have declined to 50% effectiveness, timely patching remains the most reliable defense against such exploits.

The broader cybersecurity landscape in Malaysia reflects global challenges, with ransomware and state-sponsored actors increasingly targeting critical infrastructure. The active exploitation of CVE-2026-33824 highlights the need for proactive vulnerability management, particularly as organizations grapple with the rapid adoption of cloud services and remote work environments. Failure to address this flaw could expose Malaysian enterprises to data breaches, operational disruptions, and financial losses, reinforcing the importance of adhering to CISA’s guidance and maintaining cybersecurity protocols.

Related: Microsoft

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.