Summary
Two Windows flaws under active exploitation this month start small and chain into bigger trouble. CVE-2026-21525 is a denial of service flaw in the Windows Remote Access Connection Manager (RASMAN) that a standard user can trigger to crash the VPN service and cut remote endpoints off from IT entirely. Ryan Braunstein, Security Manager at Automox, describes that as chaos in a large organization. Attacking a wide array of devices ties up the help desk while the attacker swings in with something different. Seth Hoyt, Senior Security Engineer, covers CVE-2026-21510 and CVE-2026-21514, a pair of SmartScreen bypasses that let internet-downloaded files run without the usual warning, opening a path to malware once a user clicks. Both threads run back to phishing, and the two discuss how AI is lowering the barrier to entry so a single attacker can craft convincing emails and run agents to act like a full team.
)
)
)
)
)
)