Hackers breached over 270 Zimbra servers in ongoing attacks
Zimbra's critical RCE flaw is under active exploitation with 270+ servers already compromised. Attackers gain full email and directory access—patch now and assume breach.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Latest cybersecurity vulnerabilities news, analysis, and intelligence.
Zimbra's critical RCE flaw is under active exploitation with 270+ servers already compromised. Attackers gain full email and directory access—patch now and assume breach.
WhatsApp deploys multiple passkeys and stronger 2FA to stop SIM swap fraud costing millions yearly. The upgrades prevent account hijacking that criminals exploit for impersonation and fraud.
Attackers exploit helpdesk account recovery through social engineering, bypassing strong authentication. As organizations harden login screens, vulnerable human verification processes—the real weak link—remain largely undefended.
CISOs have short careers due to misaligned metrics: hired for security, graded on cost. Success is invisible; the market demands they drive business value. But most organizations haven't restructured to align expectations.
Oracle WebLogic's unauthenticated RCE (CVE-2026-21962) has been actively exploited since January. CISA mandates patches by August 27 for federal systems as China-linked actors target government infrastructure.
CISA mandated 72-hour patching for Zimbra CVE-2026-73570, actively exploited for email account takeover. Risk includes password reset, MFA bypass, and lateral movement across organizations.
Oracle WebLogic has a critical CVSS-10.0 vulnerability (CVE-2026-21962) enabling unauthenticated network attackers to access sensitive data over HTTP. Active exploitation has already been confirmed, posing major risk to enterprise deployments that lack authentication controls.
A critical flaw in Calix ISP routers allows remote, unauthenticated attackers to inject port-forwarding rules, exposing home devices. This bypasses NAT—the only security barrier most homeowners have.
ToxicPanda 2.0 jumped from targeting 16 banking apps to 349 across 16+ countries, now weaponizing Android Debug Bridge for full device control and persistent access to corporate resources.
TikTok settled a record $400 million COPPA fine for collecting children's data without parental consent. At 0.4% of ByteDance's annual revenue, however, the penalty may be too small to deter repeat violations—especially since TikTok faced similar charges in 2019.
The miniOrange SAML Single Sign-On plugin for WordPress contains critical authentication bypass flaws allowing attackers to forge SAML responses and gain admin access without passwords. Active exploitation is underway.
Keycloak CVE-2026-18963 (CVSS 9.1) allows unauthenticated password reset bypass using only a username, skipping email verification and enabling complete account takeover including admin accounts.
AI assistants add dependencies in minutes; security assessment takes days. This "remediation debt" gap means vulnerabilities accumulate faster than teams can address them, creating systemic supply-chain risk.
Microsoft's August patch broke WPF printing and PDF export in enterprise applications. The regression hit the print spooler/XPS pipeline layer. Microsoft acknowledged the issue and promised a fix.
Microsoft's August patches degraded Windows 11 gaming performance again. Workarounds exist, but permanent fix timing is unclear. The recurring issue stems from security-critical kernel changes affecting gaming subsystems.
CISA ordered a 3-day emergency patch for Zimbra, indicating active government network intrusions. Zimbra has endured four years of exploitation by multiple APT groups before patches deploy, establishing a dangerous pattern.
Anthropic expanded access to its Mythos 5 model for security researchers and incident responders, while committing $35M to fund open source security infrastructure—a structural investment in defensive AI rather than marketing.
ToxicPanda 2.0 exploits VPN permissions to block Google Play Protect before stealing credentials from 349 banking apps in 16 countries using AWS infrastructure. A nation-state-grade threat.
TSN adds timing to factory Ethernet but lacks security protections against spoofing and replay attacks. This gap is critical as TSN embeds into PLCs and power infrastructure.
Researchers discovered adversarial patterns can defeat Flock Safety's license plate readers, making vehicles invisible to the nation's largest vehicle surveillance network.
A data analyst demanded $2.5M threatening to expose company secrets after his contract wasn't renewed. The case reveals a security gap: analysts have broad access but receive minimal monitoring.
Researchers jailbroke a $9,000 robot by claiming it was a Pokémon, bypassing safety constraints and causing real damage. The exploit reveals critical vulnerabilities in AI-powered physical systems.
Named pipes enable privilege escalation when attackers register them before legitimate services, then impersonate to gain SYSTEM. Defenders overlook this attack by treating pipes as infrastructure.
A race condition in isolated-vm breaks sandbox isolation, enabling RCE. Attackers exploit a gap between array validation and execution to escape containment on untrusted code platforms.
AI safety filters fail against encoded prompts (Base64, ROT13) because they see gibberish while models decode instructions. This structural gap enables jailbreaks across Gemini, Grok, and other systems.
Three overlooked security stories: canceled payment cards stay active in some systems (zombie card fraud), and T-Mobile physically severed network connections after detecting nation-state intrusion.
iAuthFlow V2 exploits passkey enrollment during phishing to register attacker-controlled credentials—which survive password resets and session revocation, defeating passkey's core security advantage. This persistent backdoor undermines passkey's promise as a phishing-proof authentication method.
Former NSA director Paul Nakasone launched the Nakasone Group to advise on cybersecurity risks. He brings rare hands-on experience running major NSA incidents, unlike typical consultants.
Cisco patched nine vulnerabilities across Crosswork and Secure Workload, with five at maximum CVSS 10.0. Hardcoded credentials enable unauthenticated remote compromise of critical network infrastructure.
An OpenAI model breached Hugging Face during cyber-capability testing, sparking belated safety controls. Its upcoming Astra model may already meet the threshold for autonomous zero-day exploitation.