Zimbra attacks breach 270+ servers
Threat actors compromised over 270 Zimbra instances in ongoing RCE attacks, prompting CISA to order urgent patching.
30 results for “attack”
Threat actors compromised over 270 Zimbra instances in ongoing RCE attacks, prompting CISA to order urgent patching.
SecurityWeek and MTSI repeat hands-on CAM training at the 25th ICS Cyber Security Conference.
InjecMEM lets attackers plant persistent instructions in AI agents' memory with a single prompt.
Chinese-speaking group automates post-breach ops, slashing response windows for defenders.
CISA adds CVE-2026-21962 to KEV catalog, citing active exploitation and urging federal agencies to patch by August 27.
Broadcom patches 91 Spring vulnerabilities, with one critical flaw exposing LDAP servers to attack.
Experts warn of resilience gaps after Iranian hackers disable a UK power plant for days.
Supply-chain attack on Android car head units turns them into proxy nodes and ad fraud tools.
Attackers target Windows named pipes; developers must verify identities, permissions, and data.
Wiz links a crates.io compromise to Sapphire Sleet, warning of broad developer exposure.
This week's threats exploit trusted components: signed drivers, legitimate apps, and AI to bypass defenses.
Ransom Busters, a fake recovery firm, steals victims' ransom payments that were meant for the original criminals.
Citrix warns of two NetScaler flaws, including an auth bypass, urging immediate patches.
US agencies warn hackers are exploiting Siemens PLCs in critical infrastructure with AI-generated scripts.
Government agencies warn of active exploitation of Siemens S7 controllers using AI-generated attack code.
Joint advisory warns of AI-powered attacks exploiting Siemens S7 PLCs across critical infrastructure sectors.
Attackers are exploiting critical MLflow and FUXA vulnerabilities to steal cloud credentials and execute code.
Experts discuss if detection-first security can keep pace as AI accelerates exploitation and shrinks patch-to-exploit timelines.
A critical AIT-GUI vulnerability could let attackers send commands to NASA spacecraft and instruments without authentication.
Pokémon Center UK cancels orders after logistics partner CEVA suffers cyberattack, exposing customer data.
A critical GitLab vulnerability could let unauthenticated attackers modify or delete public projects and user data.
France's tax agency says 678,000 people had data stolen in a credential-based attack.
Researchers say a suspected China-nexus APT used a VMware flaw to deploy ransomware as a smoke screen.
UNISOC modem flaw lets attackers escalate code execution to kernel level via video calls.
GE and Philips confirm probing Clop breach claims as the gang's PTC Windchill attacks ripple through enterprise giants.
A two-stage exploit chain can achieve full Android kernel access on Unisoc devices via VoLTE video call, with no patch.
Irregular details an incident where AI models escaped a test environment and attacked a real company due to a naming error.
Swiss messaging firm Threema faced sustained DDoS attacks this week, with changing tactics challenging defenses.
Corma's AI agents stopped a live attack in under 10 minutes while its CEO walked his dog, showing defenders can keep pace.
SOCRadar says most orgs hit in LiteLLM attack were earlier Trivy victims, not LiteLLM.