LIVE · cybersecurity feed
Live wire
CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accounts
vulnerabilityhigh

CISA orders urgent patching of actively exploited Zimbra flaw

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]

zeroday.news ·

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. government agencies patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. The deadline for Federal Civilian Executive Branch (FCEB) agencies to secure their systems was set for August 24.

The vulnerability, identified as CVE-2026-73570, is a command injection weakness found in the SNMP monitoring component of ZCS. It allows unauthenticated attackers to achieve remote code execution if SNMP notifications are enabled on the target system. The flaw stems from insufficient sanitization of untrusted input during the processing of SNMP notifications, enabling attackers to send specially crafted SMTP requests that can execute arbitrary operating system commands under the privileges of the Zimbra user.

Zimbra's security team addressed this flaw in version 10.1.20, which was released on July 20. CISA's directive follows an alert from CERT Polska, the Polish Computer Emergency Response Team, which first reported active exploitation of the vulnerability last Monday. CISA confirmed CERT Polska's findings and subsequently added CVE-2026-73570 to its Known Exploited Vulnerabilities (KEV) catalog.

While CISA has not disclosed specific details regarding the ongoing attacks, CERT Polska has advised security teams to examine logs for unusual activities. These include unexpected restarts of the Zimbra service and the presence of files created by the 'zimbra' user in the `/opt/zimbra/jetty/webapps/`, `/opt/zimbra/jetty_base/webapps/`, and `/tmp/` directories over the past 30 days.

ZCS is a widely used email and collaboration platform, serving numerous organizations and individuals globally, including government entities and businesses. Zimbra security vulnerabilities have frequently been targeted in the past, leading to data theft from vulnerable email servers.

Previous incidents include exploitation by APT28, a state-sponsored threat group, which utilized a stored cross-site scripting (XSS) vulnerability in attacks against Ukrainian government ZCS servers, as reported in March. In October 2024, U.S. and UK cyber agencies issued warnings about APT29, also known as Midnight Blizzard or Cozy Bear, targeting Zimbra servers with a flaw previously used to steal email account credentials. Additionally, the Russian cyber espionage group Winter Vivern has exploited a reflected Cross-Site Scripting (XSS) vulnerability to compromise emails of individuals and organizations aligned with NATO via Zimbra webmail portals.

Shadowserver, a threat security watchdog, currently tracks over 12,000 Zimbra servers exposed on the internet, though it is unclear how many of these are honeypots or have already been patched against CVE-2026-73570.

vulnerabilitypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Rethinking Application Security for the AI Era

As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. The post Rethinking Application Security for the AI Era appeared first on SecurityWeek.

security

Venezuelan Gets Record Federal Prison Term for ATM Jackpotting

Juan Manuel Gouveia-Aguilera has been sentenced to 8 years in prison for his role in an ATM jackpotting scheme that caused millions in losses. The post Venezuelan Gets Record Federal Prison Term for ATM Jackpotting appeared first on SecurityWeek.

securitycritical

CISA’s logging guidance works beyond government

The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? The Logging Reference Architecture (LRA), released in August 2026, is meant to help US federal civilian agencies meet the logging requir

nation-state

Criminal Deception in Silicon Valley

Interesting paper: Abstract: With entrepreneurial fraud cases on the rise, we investigate how entrepreneurs carry out criminal deception, employing deceptive means to defraud audiences. Analyzing court data from Silicon Valley ventures and their founders prosecuted for fraud between 2000 and 2023, our findings reveal that entrepreneurs carry out criminal deception through a process of façading: En

security

Security vets rally around $4 paper password books for sale in Australia

Once shunned by the IT crowd, pen-and-paper password vaults are getting the love they deserve in 2026

breach

Personal Information Exposed in Apollo Global Data Breach

The private equity firm appears to have been targeted as part of a campaign focusing on major financial companies. The post Personal Information Exposed in Apollo Global Data Breach appeared first on SecurityWeek.