Tech News
← Home  ·  All topics

Shadowserver Foundation

2 GoKawiil briefs on this topic

Zimbra flaw CVE-2026-73570 exploited to steal emails, Microsoft says

Microsoft reports that attackers have been actively exploiting a critical unauthenticated command-injection vulnerability in the Zimbra Collaboration Suite, tracked as CVE-2026-73570, to access and exfiltrate email and credential data. Synacor patched the flaw on July 20 but did not publicly disclose it for over three weeks, and the Shadowserver Foundation found 274 compromised instances among roughly 10,000 servers still running the software. Microsoft observed attackers scanning for vulnerable servers, confirming exploitation, then deploying web shells, reverse shells, and persistence tools before accessing and archiving mailbox data for transfer.

N-able rushes hotfix for critical N-central RCE flaw amid signs of active abuse

N-able released N-central 2026.3 Hotfix 4 on Saturday to fix CVE-2026-86218, a maximum-severity remote code execution bug that lets unauthenticated attackers run code on unpatched, internet-exposed servers. Shadowserver counts nearly 1,500 exposed N-central instances, mostly in the US and Europe, while security firm Huntress suspects the flaw, along with two related authentication-bypass bugs, may already have been exploited as a zero-day in at least one customer breach.