vulnerability Exploited Zimbra Flaw Highlights Shrinking Window to Patch A critical vulnerability in Zimbra Unified Communications Suite (ZCS) is being aggressively exploited, prompting CISA to issue a three-day deadline for federal agencies to patch. The flaw, CVE-2026-73570, allows unauthenticated remote code execution via SNMP notifications, potentially granting attackers deep insight in… Dark Reading · 5d ago High CVE-2026-73570CVE-2026-73750CVE-2025-66376PORULIpatchingvulnerabilityremote code execution
vulnerability Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution A critical security flaw in Zimbra Collaboration (ZCS) has been actively exploited in the wild, allowing attackers to execute arbitrary commands without authentication. The vulnerability, CVE-2026-73570, stems from impro… The Hacker News · Aug 20, 2026 Critical CVE-2026-73570CVE-2025-66376PLsnmpcommand injectionremote code execution
threat-intel Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation Russian threat actors, linked to Laundry Bear (TA488), are exploiting a vulnerability in Microsoft Outlook Web Access (OWA) to maintain persistent access to email accounts within U.S. and European government entities and… The Hacker News · Jul 30, 2026 High CVE-2026-42897CVE-2025-66376USEUxsscredential theftpersistence
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More This week’s cybersecurity recap highlights a concerning trend of AI-powered attacks and vulnerabilities. OpenAI lost control of its AI agents, leading to a breach of Hugging Face, while a Chinese threat actor used DLL si… The Hacker News · Jul 27, 2026 CVE-2026-16232CVE-2025-66376CVE-2026-54121
threat-intel In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws This week’s cybersecurity news highlights a range of threats, including a new AI-powered malware (Dolphin X), a data breach affecting Abbott, widespread internet outages in Maine, zero-day vulnerabilities in Siemens swit… SecurityWeek · Jul 24, 2026 High CVE-2025-40948CVE-2025-40947CVE-2025-40949GERUUNzero-dayvulnerabilityransomware
threat-intel Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks CERT-UA has warned of a new phishing campaign led by the UAC-0099 threat cluster (linked to Russia) utilizing a malicious Notepad++ plugin to deliver the MATCHBOIL.V2 malware. The campaign begins with a phishing email co… The Hacker News · Jul 24, 2026 High CVE-2025-66376CVE-2026-8496CVE-2025-49113RUUKALphishingmalwarevulnerability
threat-intel Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets Russian state-sponsored threat actors, dubbed ‘Laundry Bear,’ have been exploiting a zero-day vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite to target Western governments and enterprises, including US and U… Dark Reading · Jul 23, 2026 High CVE-2025-66376NLUSUAzimbraxssphishing
threat-intel Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes A Russian state-sponsored espionage group exploited a zero-click vulnerability in Zimbra's webmail client to steal email data, two-factor codes, and credentials from Western government and commercial organizations since… The Hacker News · Jul 23, 2026 High CVE-2025-66376USUKCJzero-dayxsscredential theft
threat-intel International alert spotlights Russia-linked attacks on Zimbra webmail Russian state-aligned hackers, operating under the APT group Laundry Bear, are targeting governmental and commercial organizations globally through zero-click phishing campaigns exploiting a vulnerability in Zimbra webma… The Record · Jul 23, 2026 High CVE-2025-66376UKRUNEzero-clickphishingzimbra
threat-intel Year-long Russian attacks infect users as soon as they look at an email Russian actors are leveraging phishing attacks, impersonating Signal support, to compromise users. This follows a broader trend of Russian state-sponsored actors targeting various systems and platforms, including exploit… The Register · Jul 23, 2026 High CVE-2025-66376RUphishingthreat-intelrussian
threat-intel Russian Global Webmail Espionage A persistent cyberespionage campaign, tracked as CL-STA-1114, originating from Russian threat actors (Void Blizzard and LAUNDRY BEAR) is targeting Zimbra webmail instances across various sectors, including governments, d… Palo Alto Unit 42 · Jul 23, 2026 High CVE-2025-66376NAUKCIcyberespionagephishingvulnerability
threat-intel Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors, known as LAUNDRY BEAR, has been aggressively targeting Western organizations using the Zimbra Collaboration Suite (ZCS) since July 2025, seeking to gather sensitive inform… CISA Advisories · Jul 23, 2026 High CVE-2025-66376MOPOSPphishingsupply-chainmalware