Threat actors have compromised over 270 Zimbra Collaboration Suite instances through remote code execution attacks exploiting a high-severity vulnerability. The ongoing campaign targets organizations worldwide.
The attacks leverage a critical vulnerability in Zimbra's email and collaboration platform, allowing attackers to execute arbitrary code on affected servers. Security researchers identified the breach after monitoring suspicious activity across multiple Zimbra deployments.
Zimbra Collaboration Suite is widely used by enterprises and government agencies for email, calendar, and messaging services. The compromised instances span multiple sectors and geographic regions.
Zimbra has released security patches addressing the vulnerability. The company recommends immediate updates for all affected installations. Organizations running ZCS should verify their systems against compromised server lists and audit logs for unauthorized access.
Security teams investigating the breach found evidence of data exfiltration on some compromised servers. The full scope of stolen information remains under investigation.
This marks the latest in a series of supply chain and platform-specific attacks targeting widely-deployed enterprise software. Administrators unable to patch immediately should isolate affected systems from network access.
WhatsApp is rolling out enhanced account security features including support for multiple passkeys and upgraded two-step verification. The changes replace the previous six-digit PIN system with stronger alphanumeric passwords.
Top Chinese military strategists have published analyses detailing artificial intelligence's role in accelerating command decision-making. The writings offer insight into Beijing's military modernization efforts.
Chinese state-backed hacking groups have more than doubled their cyberattacks since adopting AI models to generate exploit code and scan networks, according to Taiwanese cybersecurity firm TeamT5.
AliExpress deployed an outdated browser fingerprinting technique using ultrasonic frequencies to identify and track users. Security researchers discovered the e-commerce platform embedding inaudible sounds in web pages to create unique device signatures.