Zimbra RCE Is Being Actively Exploited Against Internet-Facing Servers
Attackers are actively exploiting CVE-2026-73570 in Zimbra Collaboration, an unauthenticated command injection vulnerability affecting deployments with the optional SNMP package and notifications enabled. Successful exploitation allows arbitrary operating system commands to run as the Zimbra user, creating a path to persistence, mailbox access, credential theft, and further movement into affected environments.
Source: Centre for Cybersecurity Belgium
MLflow Flaw Is Exploited to Steal Cloud Credentials and Secrets
Attackers are exploiting CVE-2026-64849, an unauthenticated SSRF vulnerability in MLflow, to reach cloud metadata services and extract credentials and other secrets. Exploitation began within hours of the CVE assignment, and CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalog.
Source: The Hacker News
VMware vCenter Exploitation Expands Into a Global Campaign
Incident responders are tracking global exploitation of CVE-2026-59310, a critical vCenter Server vulnerability that can lead to arbitrary code execution. The campaign has been linked with moderate confidence to a suspected China-nexus actor and includes reverse SSH tooling for persistent access to compromised virtualization infrastructure.
Source: QUIRSO
macOS Screen Sharing Authentication Bypass Is Exploited in the Wild
CVE-2026-65400 in macOS Screen Sharing is being exploited against reachable systems to install Monero cryptocurrency miners. The flaw allows attackers to bypass authentication to the built-in remote-control service without valid credentials, making exposed Screen Sharing services particularly risky.
Source: Malwarebytes
Adobe Commerce Vulnerability Triggers Active Exploitation Warning
Belgium’s cybersecurity authority warned organizations about active exploitation reports involving critical Adobe Commerce and Magento vulnerabilities disclosed in August. The most severe issues can enable privilege escalation, arbitrary code execution, and security control bypass, putting exposed e-commerce environments and their data at immediate risk.
Source: Centre for Cybersecurity Belgium
US Agencies Warn of Active Threat Targeting Siemens S7 PLCs
The NSA, CISA, FBI, DOE, and EPA warned critical infrastructure operators that threat actors are actively targeting Siemens S7 programmable logic controllers. The activity combines internet reconnaissance, known weaknesses, and AI-generated exploitation tooling that can manipulate PLC memory, configuration data, and control logic.
Source: CISA
North Korean Hackers Linked to Major Rust Supply Chain Compromise
Malicious releases of popular Rust crates including arrayref and append-only-vec were pushed through a legitimate maintainer account and linked to North Korean threat actors. The poisoned packages introduced a malicious dependency that executes during compilation, giving the campaign a potentially large developer-side blast radius given arrayref’s extensive use across Rust environments.
Source: SecurityWeek
Cl0p Names More Than 40 Victims in PTC Windchill Campaign
Cl0p has listed more than 40 organizations allegedly compromised through exploitation of CVE-2026-12569 in PTC Windchill and FlexPLM. Additional analysis uncovered a custom Java web shell designed specifically around Windchill’s APIs, database structure, credentials, and file repositories, indicating significant preparation for large-scale data theft.
Source: SecurityWeek
Operation CameraSwarm Compromises More Than 14,000 Dahua Cameras
Researchers traced a single operator that compromised more than 14,000 Dahua IP cameras during a campaign spanning June and July. Scanning was global, but confirmed compromises concentrated heavily in Ukraine and Russia, demonstrating the scale at which exposed surveillance devices can be converted into operational intelligence assets.
Source: Hunt.io
Critical NetScaler Authentication Bypass Puts Internet-Facing Gateways at Risk
CVE-2026-19490 is a critical authentication bypass affecting Citrix NetScaler ADC and NetScaler Gateway appliances configured for gateway or AAA functionality. Remote unauthenticated exploitation requires no user interaction, and researchers expect rapid attacker interest because NetScaler systems are commonly deployed on enterprise network perimeters.
Source: Rapid7
CareCloud Breach Impact Expands to 3.7 Million People
The number of individuals affected by the CareCloud breach has risen to more than 3.7 million, significantly above the initial estimate. Attackers accessed an AWS environment associated with the healthcare technology provider and claimed to have exfiltrated information from databases hosted there.
Source: SecurityWeek
Elementor Pro File Upload Flaw Enables Unauthenticated WordPress RCE
CVE-2026-32475 in Elementor Pro allows unauthenticated attackers to bypass file-extension validation and upload executable PHP files through vulnerable Forms configurations. Successful exploitation can result in remote code execution and complete compromise of affected WordPress servers.
Source: Orca Security
Critical isolated-vm Bug Breaks Out of JavaScript Sandboxes
A critical type confusion vulnerability in the isolated-vm Node.js library can allow code intended to run inside a V8 Isolate to achieve code execution on the host. The issue is especially relevant to services that rely on isolated-vm to safely execute untrusted JavaScript workloads without full container or virtual-machine isolation.
Source: SecurityWeek
North Korean IT Workers Used Fabricated Identities to Target More Than 1,100 Companies
Recorded Future identified multiple PurpleDelta clusters associated with North Korean IT workers using fabricated personas, AI-generated profile images, identity documents, and customized AI assistants during employment operations. One cluster applied to positions at more than 1,100 organizations, and researchers assess that operators were successfully employed by at least ten companies.
Source: Recorded Future
Russian Espionage Clusters Abuse Legitimate Authentication Flows
Google Threat Intelligence Group is tracking three suspected Russian cyberespionage clusters targeting government, defense, aerospace, academic, and think-tank personnel in Europe and the United States. The groups use phishing, OAuth abuse, legitimate authentication workflows, and in some cases malware to compromise accounts while blending into normal identity activity.
Source: Google Threat Intelligence Group
AresISEC d.o.o. · Zagreb, Croatia · OIB: 49411602130 · info@aresisec.hr
Privacy Policy | Terms of Service | Responsible Disclosure
© 2026 AresISEC