ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited

infoIndustry exploited in the wildimportance 25CVE-2026-73570CVE-2026-60004CVE-2026-8452
AI summary · glm-5.3-flash

Help Net Security's weekly digest highlights 274 compromised Zimbra servers, Gitea and Citrix NetScaler KEV additions, a PaperCut zero-day, and a suspected Iran-linked power plant attack.

The roundup reports at least 274 internet-facing Zimbra instances compromised via CVE-2026-73570, critical Gitea CVE-2026-60004 added to CISA's KEV catalog after exploitation began, and previously patched Citrix NetScaler flaw CVE-2026-8452 exploited in the wild. It also covers PaperCut NG/MF zero-day attacks, a suspected Iran-linked shutdown of a UK power plant, an FBI seizure of domains tied to a China-linked group that hit NASA, DOJ and the Senate, a cyberattack disrupting Boston Scientific, and the Manchester Airports Group breach. Additional items include Chameleon SEO poisoning phishing, Android car head unit proxy botnet malware, ReliaQuest social engineering by ShinyHunters, fake OpenAI Codex macOS malware, and AI-related workforce and supply chain interviews.

  • At least 274 internet-facing Zimbra instances compromised via CVE-2026-73570, per Shadowserver Foundation.
  • CISA added Gitea CVE-2026-60004 and Citrix NetScaler CVE-2026-8452 to the KEV catalog.
  • FBI seized domains of a China-linked hacking group behind attacks on NASA, DOJ and the U.S. Senate.
  • Boston Scientific suffered a cyberattack causing network outages; ReliaQuest employee fell for social engineering.
  • Cybersecurity job ads demanding AI skills doubled in a year in G7 countries.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-60004
Unauthenticated RCE in Gitea via diffpatch API Git Hook Injection

Gitea before 1.27.1 contains a critical code injection flaw (CWE-94) in the diffpatch API that allows remote code execution by causing the installation of a Git hook. An attacker can submit a crafted request through the diffpatch API to plant a Git hook, which then executes arbitrary shell commands on the server when Git operations run; the CVSS vector indicates the attack requires no authentication or user interaction, while public reporting describes attackers with repository write access planting hooks to run shell commands. Successful exploitation yields full server compromise (confidentiality, integrity, and availability all rated high), and observed attacks have reportedly dropped a cryptocurrency miner. All Gitea deployments running versions prior to 1.27.1 are affected, with internet-facing instances at greatest risk; public scans identified over 8,300 vulnerable Gitea servers. The flaw is actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-25, and EPSS estimates an 86.8% probability of exploitation within 30 days.

Do: Upgrade Gitea to version 1.27.1 or later immediately; organizations subject to BOD 26-04 must apply the vendor mitigation or discontinue use of unpatched cloud-hosted instances. Until patched, limit internet exposure of Gitea servers and inspect repository hook directories for unauthorized or recently modified hooks that could serve as persistence. Check for signs of compromise, including unexpected processes or cryptocurrency-miner activity, since in-the-wold attacks reportedly deploy a miner.

9.887% KEV PoC ×4
  • Gitea all versions before 1.27.1
moderate≈8,300+ internet-exposed Gitea servers (public scan count)
CVE-2026-73570
Unauthenticated OS Command Injection RCE in Synacor Zimbra Collaboration Suite

CVE-2026-73570 is an OS command injection vulnerability (CWE-78) in Synacor Zimbra Collaboration Suite (ZCS) before 10.1.20, caused by improper sanitization of untrusted input during SNMP notification processing. It is triggered when the optional zimbra-snmp package is installed and SNMP notifications are enabled: an unauthenticated attacker sends specially crafted SMTP requests that the flawed notification path turns into execution of arbitrary operating system commands. Successful exploitation runs commands as the Zimbra user, giving attackers control of the mail server's service account with high confidentiality and integrity impact across the host. Only ZCS deployments running the optional SNMP component with notifications enabled are vulnerable; other Zimbra installs are not exposed to this specific flaw. The flaw is under active exploitation: CISA added it to the KEV catalog on 2026-08-21, Poland's CERT has warned of in-the-wild attacks, unpatched Zimbra servers are reported compromised, and two public proof-of-concept exploits exist.

Do: Upgrade to Zimbra Collaboration Suite 10.1.20 or later per vendor instructions; as an interim mitigation, disable SNMP notifications or remove the zimbra-snmp package on hosts that do not need it. Federal operators must satisfy the CISA KEV/BOD 26-04 requirement, and all administrators of internet-facing Zimbra servers should hunt for signs of compromise (unexpected processes or persistence under the zimbra user) since unpatched systems are already being exploited.

8.932% KEV PoC ×4
  • Synacor Zimbra Collaboration Suite (ZCS) before 10.1.20 (when the optional zimbra-snmp package is installed and SNMP notifications are enabled)
large≈10,000-50,000 internet-exposed ZCS servers, with only the subset running zimbra-snmp with notifications enabled actually vulnerable
CVE-2026-8452
Memory Buffer Overflow in Citrix NetScaler ADC/Gateway Exploited in the Wild

CVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that applies when the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. The flaw is reachable over the network without authentication (CVSS 4.0: AV:N/PR:N), so an unauthenticated attacker can trigger it remotely. Successful exploitation causes unpredictable or erroneous appliance behavior and denial of service, and the high confidentiality score suggests possible disclosure of memory contents; some reporting suggests pre-authentication remote code execution may be possible, though the vendor description emphasizes DoS. Organizations running affected NetScaler appliances in a Gateway or AAA role — a very common configuration for remote access to Citrix virtual apps and desktops — are potentially exposed. The flaw was added to CISA's KEV catalog on 2026-08-26 and is reported as exploited in the wild, with headlines noting the flaw was already patched before exploitation was confirmed.

Do: Upgrade NetScaler ADC and Gateway to the fixed releases identified in Citrix security advisory AV26-645 (Update 3); no fixed version numbers were included in this data, so consult the advisory directly. Prioritize any appliance with an internet-exposed Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server, and given the KEV listing and reports of exploitation, perform log and forensics review for signs of prior compromise per CISA's Forensics Triage Requirements — federal agencies must comply with BOD 26-04 timelines. Where patching cannot happen immediately, restrict or disable exposed Gateway/AAA configurations as an interim mitigation.

8.82% KEV
  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway
largeTens of thousands of internet-exposed appliances (a Gateway/AAA-configured subset of the roughly 100k+ NetScaler devices visible in public internet scans) —…
Full article1,275 words · extracted from helpnetsecurity.com · click to collapse

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Week in review

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday.

AI supply chain risk is showing up in developer workflows first
In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mostly in research demos.

Suspected Iran-linked attack knocked UK power plant offline for days
News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attacks.

Production data in testing is still common, and Tricentis’ CISO wants it gone
In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-teaming and held a release for a week until it was fixed.

CISA’s logging guidance works beyond government
The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward?

AI will not fix a governance problem in your camera estate
Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody holds the admin credentials.

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.

What 90 days and a small budget can buy in AI agent security
In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, and why hardening and incident response become the buyer’s job.

Fake bank websites play dead to evade security scanners
A phishing method, named Chameleon SEO Poisoning, that uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners has been discovered by Fortra.

Android car head units infected with proxy botnet malware through built-in software updaters
A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in a proxy botnet, Kaspersky has found.

PaperCut NG/MF vulnerabilities exploited in zero-day attacks
PaperCut Software has identified the two vulnerabilities chained in these attacks and urged users to install a second patch.

Cybersecurity job ads demanding AI skills double in a year
Job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium.

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack
Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system.

Fake OpenAI Codex download tricks macOS users into installing malware
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks.

Bogus recruiters go after high-value corporate credentials on mobile
Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium.

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes
A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found.

FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate
The Justice Department and FBI have seized domains tied to two hacking tools built and run by a Chinese state-sponsored group, cutting off access to malware that had been used against U.S. government agencies for years.

Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452)
CISA added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, that is being exploited in the wild.

Cyberattack causes network outage at Boston Scientific, disrupts global operations
Medical technology company Boston Scientific suffered a cyberattack that disrupted its IT systems and caused a network outage, affecting global operations.

Manchester Airports Group breached, millions of customers’ data stolen
Someone broke into the systems of Manchester Airports Group (MAG) and walked away with a “quantity” of customer data from three UK airports, the company has confirmed.

North Korean remote workers are broadening their job hunt beyond IT
North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK workers employed in sales and marketing and the medical profession.

Two alleged TeamPCP hackers arrested over global supply chain attacks
Two men from Western Australia have been charged after police allege they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software, then used it to break into organizations around the world.

Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping
Google introduced a batch of network security changes coming in Android 17, aimed at making it harder for network operators, snoops, and scammers to track what you do on your phone.

The cybercrime supply chain has five stages, each with a price
In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date.

Ransomware attackers are zeroing in on mid-market companies
Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite.

HOL Guard: Open-source antivirus for AI agents
HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your own machine, and a typical check takes under 50 milliseconds.

Hottest cybersecurity open-source tools of the month: August 2026
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings.

Product showcase: AI Paper Trail shows the privacy cost of talking to AI
Proton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see.

Cybersecurity jobs available right now: August 25, 2026
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.

New infosec products of the month: August 2026
Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, Abnormal AI, F5 Networks, Intezer, Netscout, ScienceLogic, Searchlight Cyber, SelectHub, ServiceNow, Snyk, Tanium, and Tufin.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/30/week-in-review-compromised-zimbra-servers-previously-patched-citrix-netscaler-flaw-exploited/