1 min read
Threat Report 10/29/25
A Vulnerability in Microsoft Windows Server Update Services (WSUS) Could Allow for Remote Code Execution A vulnerability has been discovered in...
Attackers have compromised more than 270 Zimbra servers by exploiting CVE-2026-73570, a high-severity remote code execution vulnerability in Zimbra Collaboration Suite (ZCS).
The flaw can allow an attacker to execute operating system commands through specially crafted SMTP requests. Zimbra released a patch on July 20, and CISA required federal agencies to remediate the vulnerability by August 24.
The exposure remains significant: Shadowserver reported at least 8,200 unpatched Zimbra instances accessible from the internet as of August 24, although not all were necessarily exploitable.
➡️ What to do: Organizations running Zimbra should verify that the latest security updates have been applied immediately and review affected systems for evidence of prior compromise.
Read the BleepingComputer report | CVE-2026-73570 details
Citrix is urging customers to patch two newly disclosed vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway deployments.
CVE-2026-19490 is a critical authentication bypass vulnerability, while CVE-2026-19489 is a high-severity memory overflow vulnerability.
Citrix has not publicly confirmed active exploitation, but organizations should not wait for evidence of attacks before acting.
➡️ What to do: Identify affected NetScaler deployments, upgrade to Citrix's recommended builds, and confirm that internet-facing systems are appropriately secured.
Citrix Security Bulletin | CVE-2026-19490 | CVE-2026-19489
Meta has agreed to pay $16.68 billion to settle claims brought by 29 U.S. states involving Facebook and Instagram.
The lawsuits alleged that Meta designed its platforms to encourage addictive behavior among children, misrepresented safety risks, and improperly collected data from users under age 13.
Meta did not admit wrongdoing but agreed to platform changes intended to strengthen protections for younger users, including usage limits and additional controls around age-restricted content.
Why it matters: The settlement highlights the growing financial and regulatory consequences surrounding privacy, data governance, and the protection of minors' information.
The Bureau of Alcohol, Tobacco, Firearms and Explosives is investigating a major cybersecurity incident involving a standalone system operating separately from its primary network.
The affected environment was disconnected, and the ATF says there is currently no evidence its enterprise network, eForms platform, or other systems were affected.
The Qilin ransomware group has claimed responsibility, although the ATF has not confirmed that attribution.
Why it matters: The incident reinforces the importance of network segmentation and incident containment. Separating critical environments can help limit how far an intrusion spreads when a system is compromised.
CISA says attackers targeted more than 100 internet-exposed water and wastewater systems in July, with attacks primarily involving programmable logic controllers (PLCs) connected directly to cellular modems.
CISA is urging critical infrastructure operators to avoid connecting PLCs, HMIs, and RTUs directly to the internet. Remote access should instead pass through centrally managed security controls such as secure gateways, firewalls, or VPNs.
The incidents demonstrate how a seemingly simple connectivity decision can create a direct path into operational technology.
➡️ What to do: Critical infrastructure organizations should identify internet-exposed operational technology, eliminate unnecessary direct connections, and ensure remote access is centrally secured and monitored.
CISA Exposure Reduction Guidance | Read the SecurityWeek report
1 min read
A Vulnerability in Microsoft Windows Server Update Services (WSUS) Could Allow for Remote Code Execution A vulnerability has been discovered in...
“Fast Flux” Threatens National Security, CISA Issues Advisory On April 2nd, CISA issued a joint Cybersecurity Advisory that highlights the...
1 min read
Microsoft Office Vulnerability Enables Security Feature Bypass A newly identified vulnerability in Microsoft Office could allow attackers to bypass...