Zimbra Flaw Exploited Before Disclosure
Microsoft says attackers probed and exploited a Zimbra command injection flaw in the window between patch release and public disclosure.
30 results for “2026”
Microsoft says attackers probed and exploited a Zimbra command injection flaw in the window between patch release and public disclosure.
Microsoft says attackers chained a patched Zimbra command-injection flaw into web shells, credential theft and cloud exfiltration.
GTIG data shows vulnerability disclosures doubled in 2026 while exploitation shifted toward n-days, with AI-discovered flaws carrying a riskier profile.
F5 patched a critical BIG-IP APM zero-day exploited in remote code execution attacks, as CISA ordered federal agencies to secure networks by Friday.
ESET's 2026 SMB Cyber Risk Report finds 49% of UK small businesses hit by incidents, with AI-powered attacks adding pressure despite core tactics staying the same.
WordPress fixed a critical flaw in versions 4.7.0 through 7.1.1 that can lead to code execution on servers lacking a page-prefixed theme folder and register_argc_argv off.
Arista says attackers are actively exploiting CVE-2026-93952, a maximum-severity flaw in on-premises VeloCloud Orchestrator setups using certificate authentication.
Meta has agreed to let Prospect union access all 5,000 UK employees ahead of new employment rules coming in October 2026.
CrowdSec says about 300 repositories were hit and links the theft to a May 2026 TanStack supply chain attack.
FBI's IC3 logged nearly 61,000 impersonation complaints from January 2025 to July 2026, with average losses exceeding $26,000.
Black Kite's study reports manufacturers made up 22% of ransomware victims from April 2025 to March 2026, the fifth straight year atop the sector list.
A new 9.8-severity stack overflow lets unauthenticated attackers hit Security Management Servers as root, and it's not the first this summer.
A heap overflow in Unbound's DNSSEC validator lets attackers who control a malicious DNS zone trigger remote code execution on vulnerable resolvers.
A new IANS and Artico Search report finds average security budget growth of 5% in 2026 masks a median of 0%.
At TechCrunch Disrupt 2026, Gusto, Insight Partners, and Leland executives will debate which startup roles people should still own as AI agents take on more work.
Science Corporation's Max Hodak will argue brain-computer interfaces could replace screens at TechCrunch Disrupt 2026.
Google's September 2026 Pixel update fixes 110 flaws, including a modem zero-day exploited in limited, targeted attacks.
Acronis has disclosed CVE-2026-87886, a high-severity Linux privilege-escalation flaw in its cPanel and Plesk backup plugins, citing limited in-the-wild attacks.
Cisco warns CVE-2026-76461, a CVSS 9.8 flaw in Secure Email Gateway, is being exploited to run commands as root, with a federal patch deadline of September 17.
Microsoft has acknowledged that the September 2026 KB5002914 security update can silently break copy and paste in Excel, leaving users without error messages.
A maximum-severity path traversal bug in GitLab's repository commits API lets unauthenticated attackers read arbitrary files, and probes are already underway.
Sysdig says a hand-built toolkit let a human operator exploit a Marimo flaw in eight seconds, without any sign of LLM use.
MarketsandMarkets projects the cyber warfare market will grow from $14.99bn in 2026 to $28.75bn by 2031, driven by attacks on military systems.
A one-click flaw in Sogou Input Method allowed UNC3569 to deploy GrayRabbit malware, but the underlying Chromium engine remains outdated and unsandboxed.
TechRadar's hands-on with RayNeo's camera-free iO smart glasses finds a Life Log feature that records and summarizes daily life through microphones.
GitLab patches a maximum-severity path traversal flaw and a critical EE deserialization bug as researchers report in-the-wild probing within hours.
Wiz reports attackers chained two Artifactory token flaws to seize admin control and plant backdoors, while a third flaw was exploited separately.
Thirty-three cybersecurity M&A deals were announced in August 2026, with AI, identity, and exposure management topping the shopping lists.
Microsoft says the September 2026 Patch Tuesday update resolves a bug that reset desktop backgrounds and mouse settings on Windows 11.
Cisco says attackers are exploiting a maximum-severity Secure FMC bug, but its own July advisory points to earlier activity.