Tag

Snmp

All articles tagged with #snmp

CISA orders rapid patch for actively exploited Zimbra flaw
security20 hours ago

CISA orders rapid patch for actively exploited Zimbra flaw

CISA has ordered U.S. federal agencies to patch CVE-2026-73570 in Zimbra Collaboration Suite within three days after the flaw was actively exploited, enabling unauthenticated remote code execution via a SNMP command-injection vulnerability when SNMP notifications are enabled. Zimbra patched the vulnerability in version 10.1.20 (July 20). CERT Polska flagged exploitation in the wild; Shadowserver reports thousands of exposed Zimbra servers and hundreds of compromised instances. Authorities urge checking logs for suspicious activity and for files created by the zimbra user in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps, and /tmp over the past month. Given ZCS’s widespread use, governments and businesses remain at risk, with past campaigns tied to APT groups exploiting Zimbra flaws.

Zimbra RCE Flaw CVE-2026-73570 Actively Exploited in the Wild
technology4 days ago

Zimbra RCE Flaw CVE-2026-73570 Actively Exploited in the Wild

Polish CERT Polska reports active exploitation of CVE-2026-73570 in Zimbra Collaboration Suite, a SNMP-related command-injection remote-code-execution flaw. Zimbra patched it in 10.1.20 (July 20). Unauthenticated attackers can trigger OS commands via crafted SMTP requests when SNMP is enabled. Shadowserver lists over 12,000 exposed Zimbra servers, mainly in Europe and Asia; admins should check logs for anomalies and update to the patched release.

Russia-backed hackers weaponize home routers, US issues router-security advisory
technology1 month ago

Russia-backed hackers weaponize home routers, US issues router-security advisory

The US government warns that Russia-state hackers are compromising home and small-office routers to conceal attacks on critical infrastructure, exploiting weak SNMP configurations and default credentials to turn devices into exit nodes; the advisory urges disabling SNMP versions 1 and 2 (or SNMP entirely), using SNMPv3 if needed, disabling Cisco Smart Install, and maintaining strong passwords along with regular firmware updates to reduce risk.

Western Infrastructure at Risk: US, UK, and Russia Warn of Government Hackers and Cyber Attacks.
cybersecurity3 years ago

Western Infrastructure at Risk: US, UK, and Russia Warn of Government Hackers and Cyber Attacks.

APT28, a Russian state-sponsored hacking group, has been deploying a custom malware named 'Jaguar Tooth' on Cisco IOS routers to gain unauthenticated access to the device. The malware is injected directly into the memory of Cisco routers running older firmware versions and exfiltrates information from the router while providing backdoor access. The threat actors exploit the CVE-2017-6742 SNMP vulnerability to install the malware. Cisco recommends upgrading routers to the latest firmware, switching from SNMP to NETCONF/RESTCONF, and configuring allow and deny lists to restrict access to the SNMP interface.