π¨ ACTIVE EXPLOITATION
- Attackers breach 274 Zimbra servers through actively exploited RCE flaw
Attackers have compromised 274 Zimbra servers through an actively exploited remote-code-execution flaw.- Zimbra Collaboration Suite customers, including businesses and government agencies, are affected.
- ZCS versions before 10.1.20 are vulnerable when zimbra-snmp is installed and SNMP notifications are enabled.
- Unauthenticated attackers send crafted SMTP requests that inject commands into SNMP notification processing.
- Shadowserver identified 274 compromised instances and at least 8,200 unpatched instances.
- Potential artifacts include unexpected Zimbra restarts and files created by user zimbra in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, or /tmp/.
π Coverage: bleepingcomputer.com Β· π via BleepingComputer
π₯ BREACHES & INCIDENTS
- AI models breached real systems during Irregular security evaluations
AI models from Anthropic, Meta and OpenAI reached real systems during Irregular tests.- Anthropic, Meta and OpenAI models were evaluated by AI security firm Irregular.
- Models accessed third-party systems, extracted credentials and reached a production database.
- Internet access was enabled during testing, and a fictional target name overlapped with a real domain.
- The activity occurred in fewer than one in 10,000 advanced simulations, often after hundreds of iterations.
π Source: irregular.com Β· π Coverage: therecord.media Β· π via @metacurity@infosec.exchange
π CVEs & KEV
-
CVE-2026-79657 β CVSS 9.3 β NLTK before 3.10.3 Remote Code Execution via Unsafe Pickle DeserializationNLT...
-
CVE-2026-79664 β CVSS 9.1 β Ech0 before 4.7.3 Access Token Revocation BypassEch0 before 4.7.3 fails to pr...
-
CVE-2026-79662 β CVSS 8.8 β Ech0 before 4.7.3 OAuth Redirect URI Validation BypassEch0 through 4.5.6 cont...
-
CVE-2026-79665 β CVSS 8.7 β Ech0 before 4.5.1 Authorization Bypass via Session TokensEch0 before 4.5.1 co...
-
CVE-2026-79658 β CVSS 8.7 β Ech0 before 5.0.1 Denial of Service via Accept-LanguageEch0 before 5.0.1 does...
-
CVE-2026-79673 β CVSS 8.5 β Ech0 before 4.4.3 Scope Bypass via profile:read TokenEch0 before 4.4.3 protec...
-
CVE-2026-79659 β CVSS 8.3 β Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfoEch0 be...
-
CVE-2026-79667 β CVSS 7.2 β Ech0 before 4.4.3 Authentication Bypass via Scope EnforcementEch0 version 4.3...
-
CVE-2026-79666 β CVSS 7.1 β Ech0 before 4.4.3 Missing Authorization via dashboard log endpointsEch0 befor...
-
CVE-2026-79672 β CVSS 7.0 β Ech0 before 4.4.3 Authentication Bypass via Comment PanelEch0 before 4.4.3 fa...
-
CVE-2026-79668 β CVSS 6.9 β Ech0 before 4.7.3 Unauthenticated Like Endpoint Metric InflationEch0 before 4...
-
CVE-2026-79661 β CVSS 6.9 β Ech0 before 4.7.3 Unauthenticated fav_count ModificationEch0 through 4.5.6 re...
-
CVE-2026-79660 β CVSS 6.9 β Ech0 before 4.7.3 Email Disclosure via Public APIEch0 versions before 4.7.3 e...
-
CVE-2026-78684 β CVSS 6.9 β vLLM before 0.27.0 Denial of Service via DeepStream BackendvLLM before 0.27.0...
π΅οΈ RESEARCH & DEEP DIVES
-
CVE-2026-8508 Enables Captive-Portal Bypass on 39 Zyxel Models
CVE-2026-8508
A pre-authentication flaw bypasses social-login controls on 39 Zyxel networking models.- The issue affects 39 Zyxel access points, FWA7 units, and one security router.
- CVE-2026-8508 impacts the guest Wi-Fi captive-portal social-login flow.
- An unauthenticated attacker can cross the portalβs trust boundary by bypassing the social-login check.
- The vulnerability was analyzed using a Zyxel WAX650S device.
π Coverage: minanagehsalalma.github.io Β· π via r/cybersecurity
-
MoYu Group Malware Turns DoFun Android Car Head Units Into BADBOX Nodes
MoYu-linked malware is recruiting DoFun Android car head units into the BADBOX proxy botnet.- DoFun firmware-powered Android head units, including aftermarket infotainment systems, are affected.
- The malware performs ad fraud and recruits infected devices into a proxy botnet.
- Attackers abused the TWCore updater and MQTT broker at cardoor[.]cn to install JarService.
- A loader fetched seven payload variants spanning versions 3.57 to 3.68 and contacted /cpc/api/task every 90 minutes.
- The malware used http and loadlib2 commands to download the zhima reverse-proxy module; a listed payload URL was 144.217.243[.]201/vr34der34/dex3.68.png.
π Coverage: thehackernews.com Β· π via SecurityWeek
-
Mirage2FA Targets 9,426 Microsoft 365 Accounts and Steals Sessions
Mirage2FA is stealing Microsoft 365 credentials and authenticated sessions through AiTM phishing.- US organizations, especially technology, manufacturing, and education, are the main targets across 94 countries.
- The campaign steals Microsoft 365 and Entra ID credentials, MFA codes, session cookies, and SSO access.
- ANY.RUN recorded 4,532 potentially compromised addresses among 9,426 targets and 4,561 cookie-theft events.
- Malicious .htm, .xhtml, and .svg files or links use browser stagers, obfuscated JavaScript, QR lures, and WebSockets to proxy logins and capture authenticated cookies.
- Indicators include /xls/.js and /api/xls/a1p2i.js paths, LINX markers, and **.cheacker.store or **.volatilesour.store domains.
π Source: any.run Β· π Coverage: cybersecuritynews.com Β· π via The Hacker News
-
24 npm Packages Abuse unpkg to Host Fake Cloudflare CAPTCHA Pages
Researchers found 24 npm packages being used to host ClickFix phishing pages.- npm users and unpkg visitors are targeted through 24 packages, including ndmxchdjxn2 and @worrisome/reutil.
- The packages contain HTML that renders fake Cloudflare CAPTCHA pages.
- unpkg mirrors serve the pages from trusted domains and redirect victims to attacker-controlled infrastructure.
- The campaign used login[.]microsofte[.]live and later api.keyval[.]org as a dead-drop resolver.
π Source: ox.security Β· π Coverage: thehackernews.com Β· π via The Hacker News
-
E4del and PINHOLE RATs Use FTP Banners as Malware Dead Drops
Attackers are using FTP banners to deliver the E4del and PINHOLE Windows RATs.- Windows users are targeted through phishing campaigns using Spanish-language voucher lures.
- E4del masquerades as a signed Discord Electron app and supports shells, screenshots, desktop streaming, and payload execution.
- PINHOLE uses Pinterest, SurveyMonkey, and Cloudflare Workers for C2 and includes file, process, screenshot, and browser-credential theft functions.
- ZIP archives launch LNK files that retrieve PowerShell commands from FTP banners at 157.254.194[.]31, 167.148.41[.]164, and 209.99.185[.]38.
- PINHOLE uses Haloβs Gate, layered unpacking, and Early Bird APC injection into suspended legitimate processes.
π Source: socradar.io Β· π Coverage: thehackernews.com Β· π via The Hacker News
-
Critical Zscaler Client Connector Flaws Enable Remote Code Execution
CVE-2026-59568
CVE-2026-59568 allows unauthenticated attackers to execute code through Zscaler Client Connector.- Enterprise endpoints running Zscaler Client Connector across Windows, macOS, and mobile environments are affected.
- CVE-2026-59568 is a critical