Critical Windows RCE Under Active Exploit, Clop Custom Tooling, and MFA Bypass Phishing
This episode covers three active threats with credible paths to UK small businesses. First, CISA has added a critical Windows IKE Extension remote code execution vulnerability to its Known Exploited Vulnerabilities catalogue, confirming active exploitation against network-reachable systems. Second, Clop ransomware has returned with purpose-built tooling targeting PTC Windchill in manufacturing supply chains, deploying custom web shells designed for credential harvesting and data exfiltration. Third, the Mirage2FA phishing-as-a-service platform is bypassing multifactor authentication through adversary-in-the-middle session token theft, with over four thousand confirmed Microsoft 365 victims. Mauven explains the technical mechanisms behind each threat, identifies the specific organisations at risk, and provides actionable steps that require no budget approval: verifying Windows patch status for IKE Extension, questioning manufacturing suppliers about Windchill patching, and reviewing Microsoft 365 conditional access policies to detect session anomalies. The episode also notes FBI confirmation of Medusa ransomware breaching over five hundred US critical infrastructure organisations using living-off-the-land techniques. All three primary threats demonstrate that speed of response, supplier questioning, and configuration review matter more than technology spending for most small business cyber resilience.
Chapters
IntroductionMauven introduces three threats with credible UK small business impact: a Windows vulnerability under active exploitation, Clop ransomware with custom tooling, and an MFA-bypassing phishing platform.
Windows IKE Extension RCE: CISA KEV AdditionCISA has added a critical Windows IKE Extension remote code execution vulnerability to its Known Exploited Vulnerabilities catalogue. The flaw is network-reachable, requires no authentication, and allows arbitrary code execution. Mauven explains why active exploitation status demands immediate Windows patch verification, particularly for organisations using Windows-based VPN solutions.
Support the ShowBrief call to action encouraging listeners to follow the show and share with business owners who need operational threat intelligence.
Clop Returns with Purpose-Built ToolingClop ransomware is targeting PTC Windchill in manufacturing and engineering supply chains using custom-developed web shells. ReliaQuest analysis confirms the toolkit includes credential harvesting, database enumeration, and Java-based exfiltration components. Mauven explains the supply chain exposure risk and recommends questioning suppliers about Windchill patching status.
Mirage2FA Phishing-as-a-Service Bypasses MFAMirage2FA operates as an adversary-in-the-middle proxy, capturing authenticated Microsoft 365 session tokens after users complete MFA. ANY.RUN analysis identifies over four thousand victims. Mauven explains why MFA alone is insufficient without conditional access policies detecting impossible travel and anomalous session use.
Medusa Ransomware ContextFBI confirms Medusa ransomware has breached over five hundred US critical infrastructure organisations since June 2021 using phishing, unpatched vulnerabilities, and living-off-the-land techniques. Mauven notes the tactics are internationally relevant and the confirmed victim count likely understates true impact.
Summary and ActionsThree actions requiring no budget: verify Windows IKE Extension patch deployment, question manufacturing suppliers about PTC Windchill patching, and review Microsoft 365 conditional access configuration to detect session token theft. Mauven emphasises that difficulty having these conversations is itself diagnostic of resilience gaps.
Links
https://www.cisa.gov/known-exploited-vulnerabilities-cataloghttps://www.reliaquest.com/blog/clop-ransomware-ptc-windchill-cve-2026-12569/https://any.run/cybersecurity-blog/mirage2fa-phishing-kit-analysis/https://www.fbi.gov/news/press-releases/fbi-issues-alert-on-medusa-ransomwarehttps://www.ncsc.gov.uk/collection/supply-chain-security