Threat actors have already compromised more than 270 Zimbra instances in attacks that let them run code remotely. These attacks focus on a serious flaw in the Zimbra Collaboration Suite (ZCS). Synacor fixed the security flaw (called CVE-2026-73570). This flaw lets attackers run code from far away by using a …
Read More »
Chameleon SEO Poisoning
Hackers poison Bing and Google search results to deliver phishing banking pages
Bank customers looking for a login page can now fall into a trap before getting a strange email or text. Hackers are changing Google and Bing results so fake banking pages show up where people think they will find real services. The Chameleon SEO Poisoning campaign turns regular searches for …
Read More »Five new malware families actively targeting Asian Gov.t infra
Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of remote access tools. The action called SilkParasite used fake government documents and trusted Windows programs to secretly install malware on victims’ computers. The campaign seems to be aimed at intelligence gathering …
Read More »Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution
Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI Toolkit, and Splunk Connect for Kafka. The biggest flaw, listed as CVE-2026-76404, is a serious flaw that allows remote code execution. It has a CVSS score of 9.1. The notice …
Read More »Oracle Issues 943 Security Patches, Including Critical WebLogic Flaw
Oracle has put out 943 new security updates in its August 2026 Critical Security Patch Update. These updates fix problems in its business software. The update contains important Oracle WebLogic Server problems. These issues can let a remote attacker, who is not logged in, gain full control of the affected servers. …
Read More »Apple Patches 28 Security Flaws in macOS, iOS, and iPadOS
Apple has put out security updates for macOS, iOS, and iPadOS. These updates fix 28 problems that could let users lose data, crash apps, access kernel memory, and run unwanted code. The updates came out on August 17, 2026. They have macOS Tahoe 26.6.2, iOS 26.6.1, iPadOS 26.6.1, iOS 18.7.10, and …
Read More »DoNot (APT-C-35) Targeting Bangladesh Military Personnel
Bangladesh’s military and defense system is actively under targeted attack linked to DoNot Team, or APT-C-35, as stated in a cybersecurity advisory from BGD e-GOV CIRT. This attack aims at Bangladesh military and defense staff using fake documents that look like real info about a high-ranking officer in the Bangladesh …
Read More »
ALERT
Multiple TP-Link Flaws Allow to Bypass Auth and Escalate Privileges
TP-Link has revealed several serious security flaws in Aginet networking products managed by ISPs. This includes mesh systems, routers, PON devices, and xDSL modems. The flaws might let attackers who can connect to the network get around checks, gain higher access, steal important data, look at device files, and run …
Read More »PATCHCORD Backdoor Targets Telecom and CII In South Asia
A previously undocumented backdoor called PATCHCORD actively target telecom and critical information infrastructure (CII) in South Asia. According to Acronis Threat Research Unit (TRU), the backdoor is a C/C++ code that gets into systems using specific tricks, like fake VPN installers pretending to be Afghan Telecom (AFTEL) and telecom management …
Read More »Fortinet Fixes Multiple Flaws in FortiWeb, FortiManager, and FortiClient
Fortinet has released fixes for a set of authentication flaws in its FortiWeb, FortiManager, and FortiClient products. It warns admins to update quickly because these systems are sensitive. The severe one, known as CVE-2026-26035, is found in FortiWeb’s login system. It has a CVSS score between 8.8 and 9.8 based …
Read More »
InfoSecBulletin Cybersecurity for mankind