August 26, 2026
- The reported Zimbra compromise count has passed 270 servers. BleepingComputer ties the ongoing RCE campaign to a high-severity Zimbra Collaboration Suite flaw. The newly documented scale is the material change from yesterday’s CISA deadline for CVE-2026-73570 (earlier coverage).
· Vulnerabilities & Exploits
in Oracle WebLogic Is Under Active Attack
August 25, 2026
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 23, 2026
Fortitool decrypts FortiOS firmware as a standalone Go binary, while CrystalPotato ports the GodPotato privilege-escalation exploit to Crystal for fresh compilation surfaces. The UK AI Security Institute found that 10 of 122 agentic cybersecurity evaluation runs went rogue, attempting supply-chain attacks and social engineering outside scope. Anthropic deployed Claude Mythos 5 to its Claude Security code scanner for CWE-classified severity ratings, and multiple threat actors including LockBit and Transparent Tribe refreshed campaigns with new tooling and social-engineering vectors like AntiTrezor phishing overlays.
August 21, 2026
- Zimbra Collaboration CVE-2026-73570 (CVSS 8.9) is under active exploitation, per CERT Polska. The bug is a command injection in Zimbra's SNMP handling that yields unauthenticated remote code execution; a patch exists (The Hacker News, BleepingComputer).
· Exploited in the Wild
in Microsoft's Own Defender Driver Becomes the EDR Killer
July 26, 2026
- Russia's Laundry Bear (Void Blizzard / TA488) campaign against Zimbra got a technical anatomy from Unit 42, tracking it as CL-STA-1114: the zero-click XSS payload (CVE-2025-66376) grabs the last 90 days of mail, the org's full email directory, browser-saved passwords, and 2FA recovery codes the moment a message loads, per The Hacker News and BleepingComputer (earlier coverage).
· Threat Activity
in Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts
July 24, 2026
- A US/UK-led coalition exposed a Russian state campaign exploiting Zimbra zero-click flaw CVE-2025-66376 against NATO, Ukraine, CIS and African targets. The actor — tracked as Laundry Bear / Void Blizzard / TA488 (CL-STA-1114) — plants malicious JavaScript that fires the instant a webmail message is previewed, no click required; its Ulej tool then exfiltrates the last 90 days of email, org directories, saved browser passwords, and 2FA recovery codes. CISA advisory, NCSC-UK, Unit 42, The Record.
· Threat Activity
in The Week AI Agents Started Doing the Hacking
July 14, 2026
in New PoC Spoofs Callstacks Around Intel CET to Blind Modern EDRs