
Security News
The latest security stories, summarized by AI
Featured Security Stories


CISA orders rapid patch for actively exploited Zimbra flaw
CISA has ordered U.S. federal agencies to patch CVE-2026-73570 in Zimbra Collaboration Suite within three days after the flaw was actively exploited, enabling unauthenticated remote code execution via a SNMP command-injection vulnerability when SNMP notifications are enabled. Zimbra patched the vulnerability in version 10.1.20 (July 20). CERT Polska flagged exploitation in the wild; Shadowserver reports thousands of exposed Zimbra servers and hundreds of compromised instances. Authorities urge checking logs for suspicious activity and for files created by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps, and /tmp over the past month. Given ZCS’s widespread use, governments and businesses remain at risk, with past campaigns tied to APT groups exploiting Zimbra flaws.

More Top Stories
Microsoft Entra ID CVE-2026-69836: Critical RCE Not Exploited, No Action Required
The Hacker News•5 days ago
More Security Stories

Spectre cross-tenant leak in Cloudflare Workers at 12 bps prompts stronger isolation
Researchers demonstrated a remote Spectre side-channel attack leaking a JWT from a co-located Cloudflare Worker at up to 12 bits/sec (99.16% accuracy) with attacker and victim in separate V8 isolates within the same process; Cloudflare says no customer data was accessed and has mitigated the risk in production by upgrading Dynamic Process Isolation (DyPrIs), adopting the V8 Sandbox, and deploying MPK-based in-process isolation, with no exploitation observed in three years. The study notes DyPrIs detection limitations and urges in-execution signals resilient to IO activity. Tests used Linux AMD EPYC CPUs; leakage scales with load. As of Sept 2025, Cloudflare’s hardening includes stronger DyPrIs, tighter V8 pointer limits, and rotating MPK-backed memory layouts to reduce cross-isolate leakage.

Microsoft Ties 30+ Domains to MacSync MacOS Information Stealer Infrastructure
Microsoft Defender Experts linked more than 30 web domains to the MacSync Stealer infrastructure, tracing a macOS information stealer from payload delivery through exfiltration. The campaign uses interactive zsh terminals, curl-based payload retrieval, AppleScript-assisted execution, and staging in /tmp with HTTP PUT uploads carrying chunked data. Observed exfiltration patterns and recurring endpoints (/curl/, /dynamic?txd=, /gate build) reveal rotating infrastructure, while data collected includes credentials, keys, and sensitive files. Microsoft cautions users and urges monitoring of curl uploads, API-key headers, and domain changes; Apple’s macOS protections (Terminal paste protection, pasteboard blocking, AppleScript scanning) are also relevant. The report follows similar findings from RST Cloud, which noted a static API key across several domains and parallel C2 operation across a rotating set of domains.

MacOS AmnesiaStealer Enables Live, Authenticated Browser Session Hijacking
A new macOS information-stealer, AmnesiaStealer, uses a streaming module to clone a victim’s Chromium profile into a headless browser, enabling live, authenticated-session control across 16 Chromium-based browsers via WebSocket and the Chrome DevTools Protocol. It can exfiltrate cookies, saved logins, browsing history, wallets, notes, documents, and keychain data, and is distributed through ClickFix on a fake GitHub page with a password-protected ZIP. This marks the first documented macOS malware to pair a cloned Chromium profile with CDP-based live remote control, allowing attackers to view a live screencast (~3fps) and execute actions through the victim’s browser. Users should avoid unknown terminal commands and maintain strong security practices.

Azure Credential Breach Leaks Millions of Enterprise Directory Records
A threat actor named TheHatman is selling massive Azure/Entra tenant dumps containing employee records from multiple major companies, including McDonald’s (~1.7M) and Vodafone (~425k), exfiltrated via compromised credentials. The data fields cover names, corporate emails, phone numbers, addresses, job titles, departments, and privileged accounts, enabling targeted BEC and privilege escalation. While the exact intrusion vector isn’t confirmed, researchers link the leaks to Infostealer infections and credential abuse rather than a Azure zero-day. Defenders should monitor for credential exposure, enforce MFA, and review third-party access to Azure directories to mitigate risk.}

ESP32 Tap Reveals ARINC 429 Vulnerability in Airliners
Researchers show a ground-access PoC that taps ARINC 429 avionics with an ESP32 plugged into a Boeing 737’s maintenance port, able to freeze or overwrite the MCDU display and alter FMC data, potentially reprogramming autopilot. While pilots still retain control, the proof-of-concept highlights serious security risks in airliner avionics and the need for tighter physical access controls.

Global VMware vCenter Flaw Used to Deploy Reverse SSH for Persistence
A critical vulnerability in VMware vCenter Syslog Server (CVE-2026-59310) is being actively exploited to install the open-source reverse_ssh tool, establishing a persistent outbound C2 channel for remote access. Across 47 countries, 361 victim IPs have been identified, with Germany, the U.S., Turkey, Iran, and France most affected. VMware released an emergency patch; there are no official workarounds. Researchers from QUIRSO suspect an advanced persistent threat behind the campaign and note the attackers' activity began days after the vulnerability disclosure.

NightmareEclipse Unleashes Windows Defender Zero-Day Ahead of Patch Tuesday
Security researcher NightmareEclipse has published ShieldBreak, a new Windows Defender zero-day that allegedly lets attackers gain full control of a Windows device and may bypass the RoguePlanet patch (CVE-2026-50656). Microsoft is investigating but has not confirmed the claims; external researchers say the POC is legitimate. Tests reportedly work on Windows 11 25H2, Windows Server 2025, and even Windows 10. The disclosure comes ahead of Patch Tuesday, continuing the feud between Microsoft and the researcher over Windows security.

Microsoft fixes LegacyHive Windows zero-day after Nightmare Eclipse PoC disclosure
Microsoft issued August Patch Tuesday updates to fix CVE-2026-62832, a Windows User Profile Service zero-day nicknamed LegacyHive that could let an authenticated local attacker load another user's registry hive and gain administrator privileges. The Nightmare Eclipse PoC reportedly required credentials, limiting weaponization, and defenders published Defender detection queries while 0Patch released unofficial patches; several related zero-days remain unpatched.

DEF CON attendees linked to rogue onboard Wi‑Fi phishing on Delta flight
DEF CON attendees are suspected after Delta Flight 591 (Las Vegas–Atlanta) reportedly encountered a rogue onboard Wi‑Fi network, named “Delta WiFi Fast,” with a phishing landing page designed to harvest credentials. Delta said the unauthorized network was present briefly and that the official onboard Wi‑Fi was offline for about 30 minutes; flight safety was not compromised. The FBI’s Atlanta office is investigating, with no arrests announced at this time.

Active Windows zero-day drives urgent August patch Tuesday across core services
Microsoft’s August Patch Tuesday closes 398 CVEs, including CVE-2026-68820—a use‑after‑free in afd.sys that can escalate from code execution to SYSTEM and is under active exploitation—making it the top priority; four other high‑severity flaws (CVE-2026-62878 in Windows DNS Server, CVE-2026-62893 in Windows Deployment Services, CVE-2026-62815 in Microsoft QUIC, and CVE-2026-59124 in HPC Pack) are unauthenticated RCEs whose exploitation depends on service exposure. The update also finishes a two‑part SharePoint chain (CVE-2026-55040 and CVE-2026-63520) first disclosed by Rapid7. Prioritize systems with exposed DNS/WDS/QUIC/HPC services and ensure on‑prem SharePoint farms apply both July and August fixes to close the chain.