Windows & Microsoft AI News: IKE RCE & CoSnitch (Aug 20)

← Back to Blog

Windows & Microsoft AI News: IKE RCE & CoSnitch (Aug 20)

Microsoft confirms an actively exploited IKE Extension RCE, fixes Copilot Personal CoSnitch flaws, and retires AVS license-included plans. Patch now.
Windows & Microsoft AI News – Aug 20, 2026
WINDOWS AI NEWSAug 20, 20269 min read
KeyStarter logo

KeyStarter Editorial Team
AI-assisted research & drafting, editorially reviewed
Microsoft confirmed an actively exploited Windows IKE Extension RCE, shipped fixes for the Copilot Personal CoSnitch chain, and set retirement dates for license-included Azure VMware plans. In the same wave, researchers broke Windows 11 VBS and HVCI with a software-only memory attack, a deployment bug took down Microsoft 365 search, Microsoft mapped 30+ MacSync stealer domains, and Defender scans began failing after a security update.
TL;DR

  • • IKE RCE active: CISA added CVE-2026-33824 to its Known Exploited Vulnerabilities catalog; crafted packets over UDP 500/4500 can execute code as SYSTEM on unpatched Windows (LiveThreat, Aug 18, 2026).
  • • CoSnitch fixed: Microsoft patched CVE-2026-24301 on August 18; Varonis showed a crafted link could auto-run a prompt and exfiltrate data from connected Gmail, Drive, and calendar apps (The Hacker News, Aug 18, 2026).
  • • VBS bypass proven: Birmingham and Durham researchers used writable SPD chips to create memory aliases and defeat VBS and HVCI; Secure Boot blocks the current variant (University of Birmingham, Aug 13, 2026).
  • • AVS sunset set: Microsoft retires license-included Azure VMware Solution: PayGo on October 15, 2026, and all remaining SKUs on August 30, 2027 (navsplace, Aug 19, 2026).
Top picks to stay currentPrices shown at checkout · instant delivery
Product Best for Why it stands out
Windows 11 Pro

Windows 11 Pro

BEST SELLER

Everyday users & home offices Instant key delivery, lifetime support Check price
Win 11 Pro Official

Win 11 Pro Official

OFFICIAL

Businesses & compliance teams Microsoft direct order, screenshot proof Check price
Office 2021 Pro Plus

Office 2021 Pro Plus
Productivity & documents Classic perpetual license, 1 device Check price
Server IoT 2022

Server IoT 2022
Fleets & B2B infrastructure 16-core standard, lifetime support Check price
Disclosure: links go to KeyStarter products; we may earn from qualifying purchases. Prices are set at checkout.

01IKE Extension RCE Is Actively Exploited

CISA has added CVE-2026-33824, a critical remote code execution flaw in the Windows IKE Extension, to its catalog of actively exploited vulnerabilities. LiveThreat reported the details on August 18, 2026, citing BleepingComputer. An unauthenticated attacker can send specially crafted UDP packets to ports 500 or 4500 and execute arbitrary code on any unpatched Windows 10, Windows 11, or Windows Server system. The vulnerability carries a CVSS score of 9.8 and affects all supported Windows releases.

Windows IKE Extension RCE actively exploited illustration
CISA added the Windows IKE Extension RCE CVE-2026-33824 to its actively exploited catalog on August 18, 2026; patch unpatched endpoints now.

The IKE Extension negotiates IPsec VPN connections, which makes it a prime target on edge servers and remote-access gateways. The fix shipped in Microsoft’s April 2026 Patch Tuesday update, so the practical risk is concentrated on machines that never received it. CISA’s Known Exploited Vulnerabilities listing puts federal agencies on a binding patch deadline, and enterprises should treat the same urgency as their own.

For IT teams, the checklist is short: verify the CVE-2026-33824 update on every Windows endpoint, and where patching cannot happen immediately, block inbound UDP 500/4500 on systems that do not run IKE or restrict those ports to known peers. Keep patch-status evidence in the compliance repository; audit reviews increasingly ask for exactly this kind of continuous patch evidence.

02CoSnitch: One-Click Copilot Data Theft

Varonis found that a single click on a crafted link could make Microsoft Copilot Personal run an attacker’s prompt and silently pull data from connected apps, and Microsoft shipped patches on August 18. The research, named CoSnitch and tracked as CVE-2026-24301, centers on an undocumented URL parameter called autorun=1 that the assistant itself revealed during testing. Combined with the existing q parameter, a malicious prompt executes on page load inside the victim’s authenticated session with no extra click, and closing the Copilot tab does not stop it.

Copilot Personal CoSnitch one-click exfiltration illustration
Varonis named the Copilot Personal chain CoSnitch; Microsoft shipped fixes for CVE-2026-24301 on August 18, 2026.

Varonis grouped the findings into three flaws: automatic prompt execution, exfiltration through connected services, and persistent memory writes from summarized web pages. In testing, the injected prompt could return email message bodies and metadata, calendar titles and attendees, Google Drive file names and metadata, chat history, and saved user instructions. The data is base64-encoded and sent through Copilot’s built-in URL fetch, which looks like ordinary page summarization at the network layer. The third flaw lets a crafted page, when summarized, write attacker instructions into Copilot’s memory that survive password changes and session revocation.

Microsoft’s connector documentation says Copilot only works with content the account already has permission to view, and patches shipped on August 18 with no evidence of in-the-wild exploitation. The research names Copilot Personal at copilot.microsoft.com, not Microsoft 365 Copilot. Users should update Copilot, review which services are connected, and check Copilot’s memory settings for unexpected saved instructions, especially in organizations that have rolled out consumer Copilot to staff.

03Download More RAM Bypasses VBS and HVCI

University of Birmingham and Durham University researchers showed that writable SPD chips on DDR4 and DDR5 memory can create memory aliases that bypass Windows 11 VBS and HVCI with no physical access. The attack, named Download More RAM and presented at USENIX Security 2026 on August 13, exploits DIMM configuration chips that lack write protection. By rewriting the configuration from software, an attacker makes the machine report twice as much memory as it has, and the extra addresses become aliases for the real ones, defeating every access control the operating system and processor enforce.

With those aliases, the researchers re-enabled hundreds of banned known-vulnerable drivers, disabled antivirus and EDR software, read secrets inside VBS enclaves, and bypassed corporate device management and kernel-level anti-cheat. They also built a one-click script that chains the whole sequence with no user interaction. Microsoft acknowledged the findings as CVE-2026-23670 and shipped mitigations in its April 2026 security updates; Windows with Secure Boot enabled is protected against the current variant, while machines without Secure Boot remain exposed.

The survey found Corsair, G.Skill, and ADATA each ship at least one product line with the configuration chip entirely unprotected, covering 55 percent of the high-performance consumer memory market and more than 70 percent of the gaming segment. Crucial, Kingston, and HyperX use partial write protection that blocks the attack. Corsair’s iCUE tooling and the free HWinfo utility can retroactively enable write protection, and some motherboards expose a BIOS setting to block writes. For fleets, the practical defenses are Secure Boot enabled, April 2026 updates applied, and hardware write-protection tools rolled out on sensitive machines.

04M365 Search Outage Traced to Deployment Bug

Microsoft’s incident MO1456424 traced search failures across Outlook, SharePoint Online, and OneDrive to a deployment that introduced a resource-efficiency problem. 4sysops reported on August 18, 2026 that only users routed through the affected infrastructure saw failures. The deployment consumed resources incorrectly, and searches stopped working in Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive.

The impact spread beyond search: message trace collection and access to Microsoft Purview, Defender XDR, and the Microsoft 365 admin portals were disrupted, and Teams chat, meeting, and channel creation, plus presence and location information, were also affected. Microsoft reduced resource pressure by deploying a fix and restoring infrastructure to a healthy state, but full recovery required additional load balancing and routing users to alternate infrastructure.

The incident is a reminder that deployment bugs, not just capacity events, cause service outages. Administrators should verify search, portal access, message tracing, and related workflows before closing incident tickets, and treat pre-deployment load and resource testing as a release gate for tenant changes. For most users the outage was transient, but the breadth of affected services shows how one efficiency regression can cascade across a whole suite.

05Microsoft Ties 30+ Domains to MacSync Stealer

Microsoft Defender Experts linked more than 30 rotating domains to the macOS-focused MacSync Stealer and mapped its full kill chain from payload download to data exfiltration. LiveThreat summarized the findings on August 18, 2026, citing The Hacker News. By correlating recurring endpoint and network behaviors, Microsoft tied the domains to a campaign that uses fast-flux style rotation to host the stealer payload and exfiltrate harvested data over encrypted channels.

The stealer is delivered as custom-built macOS binaries, and no public CVE is associated with the campaign. The fast-flux rotation defeats static blocklists, which is why the value here is intelligence: organizations with Apple workstations can use the domain list and behavior patterns to tune monitoring, endpoint detection, and proxy rules.

For security teams, the actions are to verify that endpoint protection covers the MacSync payloads, retain domain lookup and data-flow logs as audit evidence, and strengthen security-awareness training for macOS-specific malware vectors. Even a macOS-only stealer matters to Windows-first organizations, because harvested credentials and session data often end up used against Windows and cloud services next.

06Defender Scans Stall After Security Update

Users report that Microsoft Defender quick, full, and offline scans are failing after recent security updates, and Microsoft has not yet officially acknowledged the problem. L’Informaticien reported on August 19, 2026 that some machines cannot complete quick or full scans, and offline scans also hit difficulties; one user reported the offline scan stuck at 91 percent. Manual full-disk scans still work, which points to a Defender service problem rather than the file-checking engine itself.

Event Viewer shows crashes with code 0x000005 pointing to mpengine.dll, the core of Microsoft’s antimalware engine, and DefenderApiLoggerLowPriv session errors repeat for several days. ESET researcher Aryeh Goretsky says the issue occurs in Defender versions 1.1.26070.7 and 1.1.26080.2 together with Microsoft Security Intelligence updates 1.457.222.0 through 1.457.230.0.

Because Defender is the default protection on millions of Windows machines, failed scans create a visibility gap exactly when attackers are probing Windows security. If scans fail on your machines, check Event Viewer for the mpengine.dll pattern, try a manual scan, keep definitions current, and track the issue until Microsoft ships a fix. In the meantime, do not assume a failed scan means a clean system; verify protection status through other means where possible.

07AVS License-Included Plans Retire

Microsoft will retire the license-included version of Azure VMware Solution, ending PayGo SKUs on October 15, 2026 and all remaining SKUs on August 30, 2027. navsplace reported the dates on August 19, 2026, following Microsoft’s confirmation. The change follows Broadcom’s November 2025 policy requiring portable bring-your-own-license VCF licenses on every hyperscaler, which removed the economics behind bundling VMware licenses into Azure services.

Azure VMware Solution license-included retirement illustration
Microsoft retires license-included Azure VMware Solution; PayGo SKUs end October 15, 2026 and all remaining SKUs on August 30, 2027.

Customers on license-included Reserved Instance SKUs have two realistic paths: buy portable Broadcom VCF licenses and move to the AVS VCF BYOL SKU, or migrate off AVS before August 30, 2027. Workloads that take no action face service disruption starting August 31, 2027. PayGo customers face the tighter deadline of October 15, 2026, and VCF license procurement can take four to eight weeks, so assessment needs to start now rather than at year end.

The migration is not just a billing change. VCF licenses are purchased per core, so teams must size their AVS consumption in cores, not node counts. BYOL per-node pricing is lower because it excludes the VMware license cost, but the VCF cost now sits with the customer. The same BYOL requirement applies to AWS VMware Cloud and Google Cloud VMware Engine, so switching providers does not avoid the licensing shift. Engage your Microsoft account team early, exchange RI reservations that extend beyond the retirement date, and put a dated migration plan in place.

08What This Means for Windows Users and IT Teams

This news cycle breaks into three priorities: patch Windows endpoints for the IKE RCE, verify security tooling is actually working, and start Azure VMware migration planning immediately. The IKE vulnerability is being exploited in the wild, the Download More RAM research weakens the strongest Windows defenses, and Defender scan failures create a monitoring gap at the worst possible moment.

For Windows users: apply the April 2026 IKE patch or ensure Windows Update delivered it, keep Secure Boot enabled, and update Copilot Personal while reviewing connected apps and its saved memory. If Defender scans fail, check Event Viewer and run a manual scan, and keep an eye on Microsoft 365 search and portals until incident MO1456424 is fully closed.

For IT teams: inventory unpatched Windows endpoints exposed on UDP 500/4500, block those ports where IKE is not needed, and collect patch evidence for compliance. Confirm Secure Boot and April mitigations on fleets that matter, tune detection for the MacSync domains, and put the AVS PayGo date on the calendar now. For licensing decisions that intersect with these changes, the Best Windows License Buying Guide 2026, the Windows 11 Pro vs Home guide, and the Windows 10 vs Windows 11 comparison cover the common paths.

The through-line is defense in depth: patch quickly, verify that every layer of protection is honestly healthy, and treat license and migration deadlines as security work. Teams that act this week on the IKE patch and the AVS timeline will be in a far better position than those that wait.

FAQ

Is the Windows IKE Extension RCE fixed?

Yes, for supported Windows versions, if you apply the April 2026 Patch Tuesday update. CISA added CVE-2026-33824 to its actively exploited catalog on August 18, 2026; if you cannot patch, block inbound UDP 500/4500 on systems that do not use IKE (LiveThreat, Aug 18, 2026).

Does CoSnitch affect Microsoft 365 Copilot?

Varonis says no. The research names Copilot Personal at copilot.microsoft.com, and patches shipped on August 18, 2026 as CVE-2026-24301. There is no evidence the chain was exploited in the wild (The Hacker News, Aug 18, 2026).

Can the Download More RAM attack be stopped?

Yes, in its current form. Microsoft’s April 2026 security updates plus Secure Boot enabled block the attack; machines without Secure Boot remain vulnerable. Hardware tools like Corsair iCUE and HWinfo can enable SPD write protection (University of Birmingham, Aug 13, 2026).

Are the Microsoft 365 search issues fully resolved?

Microsoft says it deployed a fix and restored load balancing, with users routed to alternate infrastructure. Administrators should verify search, portal access, and message tracing before closing tickets for incident MO1456424 (4sysops, Aug 18, 2026).

What should Azure VMware Solution customers do first?

PayGo license-included SKUs retire October 15, 2026 and all remaining SKUs on August 30, 2027. Start assessment now, budget four to eight weeks for VCF license procurement, and choose between AVS VCF BYOL or migration off AVS (navsplace, Aug 19, 2026).

External References

KeyStarter logo

By KeyStarter Editorial Team
This article was compiled with AI assistance for research and drafting and has been editorially reviewed. All sources are listed above.

← Back to all articles

This site uses cookies to improve your experience and for analytics. Privacy Policy and Cookie Policy.