Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Unpatched Zimbra servers are falling to CVE-2026-73570 attacks At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. AI supply chain risk is showing up in developer workflows first In this Help Net Sec

Attackers are actively exploiting a previously patched vulnerability in Citrix NetScaler ADC and Gateway, identified as CVE-2026-8452. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed this exploitation by adding the flaw to its Known Exploited Vulnerabilities (KEV) catalog.
In a separate development, at least 274 internet-facing Zimbra instances have been compromised through attacks leveraging CVE-2026-73570. The Shadowserver Foundation reported this widespread compromise of unpatched Zimbra servers.
CISA also confirmed that a critical code injection vulnerability in the Gitea Git platform, CVE-2026-60004, is now being exploited in the wild. This vulnerability has also been added to the KEV catalog.
PaperCut Software has identified two vulnerabilities that were chained together in recent zero-day attacks. The company has urged users to install a second patch to address these issues.
In other cybersecurity news, medical technology company Boston Scientific experienced a cyberattack that disrupted its IT systems and caused a network outage, affecting its global operations.
Manchester Airports Group (MAG) confirmed a breach of its systems, resulting in the theft of customer data from three UK airports. The company stated that a "quantity" of customer data was exfiltrated.
Cybersecurity firm ReliaQuest disclosed that one of its employees fell victim to a social engineering attack. This incident granted attackers a password and a brief window of access into the company’s identity system.
The Justice Department and FBI have taken action against a Chinese state-sponsored hacking group, seizing domains linked to two hacking tools. These tools had been used for years against U.S. government agencies, including NASA, the Department of Justice, and the U.S. Senate.
Two men from Western Australia have been charged in connection with TeamPCP, a cybercrime group accused of planting malicious code in open-source software to facilitate intrusions into organizations globally.
A newly discovered Android malware is being distributed through built-in updaters in affected Android-based car head units. This malware transforms infected devices into tools for ad-fraud and nodes within a proxy botnet.
A phishing method dubbed "Chameleon SEO Poisoning" has been identified. This technique uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners.
A malware campaign targeting macOS users involves a sponsored search ad and a fake OpenAI Codex download page. The campaign tricks users into pasting a malicious command into their Terminal.
Scammers posing as HR staff from well-known companies are running interview scheduling scams designed to steal corporate passwords.
A phishing-as-a-service (PhaaS) platform named AnonyMousKIT is automating the theft of Apple ID credentials. These credentials are used to remove Activation Lock from stolen iPhones, reportedly utilizing AI voice calls in the process.
North Korean (DPRK) remote workers are reportedly expanding their job searches beyond the IT sector, with investigations identifying suspected DPRK workers in sales and marketing and the medical profession.

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.