
Zimbra RCE flaw under active attack
CERT Polska reports active exploitation of a critical remote-code-execution vulnerability in Zimbra Collaboration Suite, urging immediate patching for affected versions.
Incidents, vulnerabilities, abuse and certificates.

CERT Polska reports active exploitation of a critical remote-code-execution vulnerability in Zimbra Collaboration Suite, urging immediate patching for affected versions.

A breach at healthcare infrastructure provider CareCloud compromised 3.75 million patient records, including Social Security numbers, medical histories, and financial details. The attackers remained undetected in the company's AWS environment for nearly a week.

Cloudflare disclosed a remote Spectre attack on its Workers platform that reliably leaked 12 bits per second with 99% accuracy, prompting runtime and isolation improvements. The exploit evaded existing defenses by exploiting long-lived execution contexts and noisy timers.

wolfSSL has removed its last dependency on the liboqs post-quantum cryptography library, replacing it with native implementations of NIST-standardized algorithms and experimental schemes like FrodoKEM and Falcon. The move targets embedded, RTOS, and hardware-backed deployments with smaller footprints and platform-specific optimizations.

CVE-2026-47876 allows a guest VM with VMXNET3 adapter to execute code on the ESX host. Patches require host restarts, while one vCenter directory-traversal flaw is already exploited in 47 countries.

A cooling system failure at a Phoenix data center operated by RadiusDC caused extended outages for Namecheap and Hosting.com, affecting shared hosting, VPS, email, and DNS management. Recovery efforts focused on restoring temperatures before staged service restoration.

Microsoft’s August security update addresses 421 vulnerabilities, including a zero-day in the Windows Ancillary Function Driver for WinSock exploited by North Korea’s Lazarus Group since early June. The campaign targeted defense contractors via fake job offers and malicious PDF viewers, deploying a new rootkit and backdoor.

The Sandworm group has been distributing a backdoored WireGuard VPN client to system administrators since at least May, using fake job offers as the initial vector.

The U.S. Cybersecurity and Infrastructure Security Agency has confirmed that ransomware groups are exploiting a remote code execution vulnerability in Microsoft SharePoint, which has been under active attack since early July.

A supply-chain compromise of BdThemes' infrastructure allowed attackers to inject rogue WordPress administrator accounts via a tampered remote JSON configuration feed, affecting users of the vendor's premium design plugins.

The U.S. Cybersecurity and Infrastructure Security Agency has added two recently patched SonicWall SMA1000 vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming ransomware gangs are actively exploiting them.

Roundcube shipped 11 security fixes in versions 1.7.3 and 1.6.18 but assigned no CVE numbers, breaking automated detection for hosting fleets. cPanel has not yet integrated the update, extending exposure windows for providers relying on its bundled package.

CISA added a critical-severity Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog after observing in-the-wild exploitation.

Hacktivist collective Head Mare exploited vulnerabilities in TrueConf servers to distribute backdoored client installers, security researchers report.

WordPress 7.0.3 addresses 12 vulnerabilities, including pre-auth XSS on the login screen, SSRF in URL validation, and a multisite privilege escalation. Sites are urged to update immediately; backports to older branches are in progress.

A Canadian national has pleaded guilty to infiltrating Snowflake customer accounts and stealing data from at least 165 organisations as part of an extortion scheme.

Attackers exploited an Oracle database SQL injection flaw to embed a post-exploitation toolkit, compromising a corporate network. The khunt toolkit was installed directly within the database environment.

TP-Link patched 15 vulnerabilities in its Omada zero-touch provisioning system, allowing attackers to combine them with earlier flaws to gain remote code execution on enterprise networks.

N-able has issued an advisory about an authentication bypass vulnerability (CVE-2026-18577) in its N-central remote monitoring and management platform, which is being actively exploited in the wild. The flaw affects both hosted and on-premises deployments.

A study by Claroty reveals that nearly one in five physical control assets in major data centers are a single network hop away from systems with outbound internet connections, creating potential attack vectors for power, cooling, and building management systems.