LIVE · cybersecurity feed
Live wire
CVE-2026-73570

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Unpatched Zimbra servers are falling to CVE-2026-73570 attacks At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. AI supply chain risk is showing up in developer workflows first In this Help Net Sec

zeroday.news ·

Attackers are actively exploiting a previously patched vulnerability in Citrix NetScaler ADC and Gateway, identified as CVE-2026-8452. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed this exploitation by adding the flaw to its Known Exploited Vulnerabilities (KEV) catalog.

In a separate development, at least 274 internet-facing Zimbra instances have been compromised through attacks leveraging CVE-2026-73570. The Shadowserver Foundation reported this widespread compromise of unpatched Zimbra servers.

CISA also confirmed that a critical code injection vulnerability in the Gitea Git platform, CVE-2026-60004, is now being exploited in the wild. This vulnerability has also been added to the KEV catalog.

PaperCut Software has identified two vulnerabilities that were chained together in recent zero-day attacks. The company has urged users to install a second patch to address these issues.

In other cybersecurity news, medical technology company Boston Scientific experienced a cyberattack that disrupted its IT systems and caused a network outage, affecting its global operations.

Manchester Airports Group (MAG) confirmed a breach of its systems, resulting in the theft of customer data from three UK airports. The company stated that a "quantity" of customer data was exfiltrated.

Cybersecurity firm ReliaQuest disclosed that one of its employees fell victim to a social engineering attack. This incident granted attackers a password and a brief window of access into the company’s identity system.

The Justice Department and FBI have taken action against a Chinese state-sponsored hacking group, seizing domains linked to two hacking tools. These tools had been used for years against U.S. government agencies, including NASA, the Department of Justice, and the U.S. Senate.

Two men from Western Australia have been charged in connection with TeamPCP, a cybercrime group accused of planting malicious code in open-source software to facilitate intrusions into organizations globally.

A newly discovered Android malware is being distributed through built-in updaters in affected Android-based car head units. This malware transforms infected devices into tools for ad-fraud and nodes within a proxy botnet.

A phishing method dubbed "Chameleon SEO Poisoning" has been identified. This technique uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners.

A malware campaign targeting macOS users involves a sponsored search ad and a fake OpenAI Codex download page. The campaign tricks users into pasting a malicious command into their Terminal.

Scammers posing as HR staff from well-known companies are running interview scheduling scams designed to steal corporate passwords.

A phishing-as-a-service (PhaaS) platform named AnonyMousKIT is automating the theft of Apple ID credentials. These credentials are used to remove Activation Lock from stolen iPhones, reportedly utilizing AI voice calls in the process.

North Korean (DPRK) remote workers are reportedly expanding their job searches beyond the IT sector, with investigations identifying suspected DPRK workers in sales and marketing and the medical profession.

vulnerabilitypatchai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilityhigh

Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch

PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the print management software running in schools, hospitals, and offices worldwide, confirmed on August 27 that a pre-authentication remote code execution flaw is being actively exploited against real customers. Researchers at Huntress found evide

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

security

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]

malware

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]

malware

Chrome Web Store extensions caught stealing crypto, browser data

Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]