View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Attackers breach 274 Zimbra servers via actively exploited RCE flaw

🚨 ACTIVE EXPLOITATION

  • Attackers breach 274 Zimbra servers through actively exploited RCE flaw
    Attackers have compromised 274 Zimbra servers through an actively exploited remote-code-execution flaw.
    • Zimbra Collaboration Suite customers, including businesses and government agencies, are affected.
    • ZCS versions before 10.1.20 are vulnerable when zimbra-snmp is installed and SNMP notifications are enabled.
    • Unauthenticated attackers send crafted SMTP requests that inject commands into SNMP notification processing.
    • Shadowserver identified 274 compromised instances and at least 8,200 unpatched instances.
    • Potential artifacts include unexpected Zimbra restarts and files created by user zimbra in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, or /tmp/.
      πŸ“Ž Coverage: bleepingcomputer.com Β· πŸ‘ via BleepingComputer

πŸ’₯ BREACHES & INCIDENTS

πŸ”“ CVEs & KEV

  • CVE-2026-79657 β€” CVSS 9.3 β€” NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle DeserializationNLT...

  • CVE-2026-79664 β€” CVSS 9.1 β€” Ech0 before 4.7.3 Access Token Revocation BypassEch0 before 4.7.3 fails to pr...

  • CVE-2026-79662 β€” CVSS 8.8 β€” Ech0 before 4.7.3 OAuth Redirect URI Validation BypassEch0 through 4.5.6 cont...

  • CVE-2026-79665 β€” CVSS 8.7 β€” Ech0 before 4.5.1 Authorization Bypass via Session TokensEch0 before 4.5.1 co...

  • CVE-2026-79658 β€” CVSS 8.7 β€” Ech0 before 5.0.1 Denial of Service via Accept-LanguageEch0 before 5.0.1 does...

  • CVE-2026-79673 β€” CVSS 8.5 β€” Ech0 before 4.4.3 Scope Bypass via profile:read TokenEch0 before 4.4.3 protec...

  • CVE-2026-79659 β€” CVSS 8.3 β€” Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfoEch0 be...

  • CVE-2026-79667 β€” CVSS 7.2 β€” Ech0 before 4.4.3 Authentication Bypass via Scope EnforcementEch0 version 4.3...

  • CVE-2026-79666 β€” CVSS 7.1 β€” Ech0 before 4.4.3 Missing Authorization via dashboard log endpointsEch0 befor...

  • CVE-2026-79672 β€” CVSS 7.0 β€” Ech0 before 4.4.3 Authentication Bypass via Comment PanelEch0 before 4.4.3 fa...

  • CVE-2026-79668 β€” CVSS 6.9 β€” Ech0 before 4.7.3 Unauthenticated Like Endpoint Metric InflationEch0 before 4...

  • CVE-2026-79661 β€” CVSS 6.9 β€” Ech0 before 4.7.3 Unauthenticated fav_count ModificationEch0 through 4.5.6 re...

  • CVE-2026-79660 β€” CVSS 6.9 β€” Ech0 before 4.7.3 Email Disclosure via Public APIEch0 versions before 4.7.3 e...

  • CVE-2026-78684 β€” CVSS 6.9 β€” vLLM before 0.27.0 Denial of Service via DeepStream BackendvLLM before 0.27.0...

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • CVE-2026-8508 Enables Captive-Portal Bypass on 39 Zyxel Models CVE-2026-8508
    A pre-authentication flaw bypasses social-login controls on 39 Zyxel networking models.

    • The issue affects 39 Zyxel access points, FWA7 units, and one security router.
    • CVE-2026-8508 impacts the guest Wi-Fi captive-portal social-login flow.
    • An unauthenticated attacker can cross the portal’s trust boundary by bypassing the social-login check.
    • The vulnerability was analyzed using a Zyxel WAX650S device.
      πŸ“Ž Coverage: minanagehsalalma.github.io Β· πŸ‘ via r/cybersecurity
  • MoYu Group Malware Turns DoFun Android Car Head Units Into BADBOX Nodes
    MoYu-linked malware is recruiting DoFun Android car head units into the BADBOX proxy botnet.

    • DoFun firmware-powered Android head units, including aftermarket infotainment systems, are affected.
    • The malware performs ad fraud and recruits infected devices into a proxy botnet.
    • Attackers abused the TWCore updater and MQTT broker at cardoor[.]cn to install JarService.
    • A loader fetched seven payload variants spanning versions 3.57 to 3.68 and contacted /cpc/api/task every 90 minutes.
    • The malware used http and loadlib2 commands to download the zhima reverse-proxy module; a listed payload URL was 144.217.243[.]201/vr34der34/dex3.68.png.
      πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via SecurityWeek
  • Mirage2FA Targets 9,426 Microsoft 365 Accounts and Steals Sessions
    Mirage2FA is stealing Microsoft 365 credentials and authenticated sessions through AiTM phishing.

    • US organizations, especially technology, manufacturing, and education, are the main targets across 94 countries.
    • The campaign steals Microsoft 365 and Entra ID credentials, MFA codes, session cookies, and SSO access.
    • ANY.RUN recorded 4,532 potentially compromised addresses among 9,426 targets and 4,561 cookie-theft events.
    • Malicious .htm, .xhtml, and .svg files or links use browser stagers, obfuscated JavaScript, QR lures, and WebSockets to proxy logins and capture authenticated cookies.
    • Indicators include /xls/.js and /api/xls/a1p2i.js paths, LINX markers, and **.cheacker.store or **.volatilesour.store domains.
      πŸ“„ Source: any.run Β· πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via The Hacker News
  • 24 npm Packages Abuse unpkg to Host Fake Cloudflare CAPTCHA Pages
    Researchers found 24 npm packages being used to host ClickFix phishing pages.

    • npm users and unpkg visitors are targeted through 24 packages, including ndmxchdjxn2 and @worrisome/reutil.
    • The packages contain HTML that renders fake Cloudflare CAPTCHA pages.
    • unpkg mirrors serve the pages from trusted domains and redirect victims to attacker-controlled infrastructure.
    • The campaign used login[.]microsofte[.]live and later api.keyval[.]org as a dead-drop resolver.
      πŸ“„ Source: ox.security Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • E4del and PINHOLE RATs Use FTP Banners as Malware Dead Drops
    Attackers are using FTP banners to deliver the E4del and PINHOLE Windows RATs.

    • Windows users are targeted through phishing campaigns using Spanish-language voucher lures.
    • E4del masquerades as a signed Discord Electron app and supports shells, screenshots, desktop streaming, and payload execution.
    • PINHOLE uses Pinterest, SurveyMonkey, and Cloudflare Workers for C2 and includes file, process, screenshot, and browser-credential theft functions.
    • ZIP archives launch LNK files that retrieve PowerShell commands from FTP banners at 157.254.194[.]31, 167.148.41[.]164, and 209.99.185[.]38.
    • PINHOLE uses Halo’s Gate, layered unpacking, and Early Bird APC injection into suspended legitimate processes.
      πŸ“„ Source: socradar.io Β· πŸ“Ž Coverage: thehackernews.com Β· πŸ‘ via The Hacker News
  • Critical Zscaler Client Connector Flaws Enable Remote Code Execution CVE-2026-59568
    CVE-2026-59568 allows unauthenticated attackers to execute code through Zscaler Client Connector.

    • Enterprise endpoints running Zscaler Client Connector across Windows, macOS, and mobile environments are affected.
    • CVE-2026-59568 is a critical

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check