Skip to content

Sam's News — security — 2026-08-25

Security

8.5 Critical Zimbra vulnerability CVE-2026-73570 allows full email account takeover

CISA has issued a three-day emergency deadline for agencies to patch an unpatched Zimbra vulnerability that allows remote attackers full access to user communications.

  • CVE-2026-73570 actively exploited
  • Affects Zimbra with optional snmp package
  • Unauthenticated remote code execution
  • Patched version 10.1.20 released July 20, 2026
  • CISA BOD 26-04: 3-day federal patching mandate

Sources: Dark Reading RSS Update to: CISA Orders Urgent Patching of Actively Exploited Zimbra Vulnerability

8 Ancient BMC vulnerability CVE-2013-4786 exposes thousands of data centers to attacks

CVE-2013-4786, a 22-year-old vulnerability in baseboard management controllers, exposes over 24,000 internet-accessible servers to authentication hash leakage.

  • CVE-2013-4786: 22-year-old IPMI 2.0 authentication protocol vulnerability from 2004
  • Over 24,000 exposed BMC servers vulnerable; ~37,000 internet-exposed IPMI interfaces affected
  • Vulnerability allows extraction of HMAC-SHA1 authentication hashes from RAKP message 2 responses
  • Compromised credentials work across Redfish HTTPS API and web-based administrative interfaces
  • 6,240 exposed hosts accept empty usernames with weak passwords

Sources: SecurityWeek AI Web Searched, SecurityWeek Web Search

8 Oracle WebLogic Server flaw under active exploitation added to CISA's Known Exploited Vulnerabilities

CISA added CVE-2026-21962, a maximum-severity remote code execution vulnerability in Oracle HTTP Server and WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog on August 25. The flaw allows unauthenticated attackers to modify or access critical data; patches were released in January 2026, and federal agencies must remediate by August 27.

  • CVE-2026-21962 added to KEV catalog August 25, 2026
  • CVSS 10.0 severity; affects Oracle HTTP Server and WebLogic Proxy Plug-in
  • Allows unauthenticated remote access to create, delete, or modify critical data
  • Patches available since January 2026
  • Federal agencies must patch by August 27, 2026 (BOD 26-04)

Sources: The Hacker News AI Web Searched

8 Mirage2FA campaign hits 4,500 US and EU companies via Microsoft 365

Mirage2FA, a phishing-as-a-service toolkit operating since 2024, targeted 4,532 organizations across the US and EU by abusing Microsoft 365 login flows and bypassing two-factor authentication. The campaign compromised roughly 48% of targeted email addresses and affected multiple industries including technology, manufacturing, and education.

  • 4,532 unique organizations targeted (63.7% US-based)
  • 48% of targeted email addresses potentially compromised
  • Steals passwords and session cookies to hijack authenticated sessions and bypass 2FA
  • 9,000+ potential compromise events involving cookie theft, SSO logins, and 2FA bypass

Sources: The Hacker News AI Web Searched

7.5 Unpatched Calix router flaw allows remote attackers to bypass NAT and expose internal networks

An unpatched vulnerability in Calix GS7 XGS residential routers used by U.S. broadband providers allows unauthenticated attackers to bypass NAT by creating port-forwarding rules, exposing internal network devices to the public internet. No patch has been released.

  • Calix GS5239XG router model affected; unpatched vulnerability
  • Unauthenticated attackers can create port-forwarding rules bypassing NAT
  • Exposes internal network devices directly to public internet

Sources: Bleeping Computer AI Web Searched, BleepingComputer RSS

7.5 AI-powered cybercrime accelerates as attackers use machine learning to expose software flaws

AI-powered cybercrime is accelerating as threat actors deploy machine learning to identify and exploit software vulnerabilities simultaneously with discovery, eliminating the traditional patching window. The Cloud Security Alliance warns CISOs must prepare for high-velocity attacks, though Anthropic temporarily constrains access to its Mythos model.

  • Anthropic's Claude Mythos AI collapses vulnerability discovery-to-exploitation into single event
  • Cloud Security Alliance published 'AI Vulnerability Storm' report warning CISOs
  • Anthropic constraining Mythos access via Project Glasswing as temporary measure
  • Nation-states and organized crime already deploying AI for zero-day discovery and exploitation chains
  • Predicted scenarios: AI-powered financial system manipulation and synthetic identity epidemics

Sources: SecurityWeek AI Web Searched, Frontier Enterprise AI Web Searched, The Hacker News AI Web Searched, The World Economic Forum Web Search

7.5 $1 trillion investment firm Apollo breached via social engineering; attackers accessed cloud platforms for four days

Apollo Global Management, a $1 trillion investment firm, disclosed a breach where attackers posed as IT helpdesk staff to gain cloud access for four days between July 6–10, 2026. Exposed data includes names, dates of birth, addresses, contact information, and Social Security numbers of employees; the attack matches a campaign against other major financial firms by threat group UNC6671.

  • Breach window: July 6–10, 2026; discovered August 12, 2026
  • Social engineering attack—posers posed as IT helpdesk
  • Exposed: names, DOB, addresses, contact info, Social Security numbers
  • Matches UNC6671 campaign targeting Blackstone, Bridgewater, Bain Capital
  • Apollo offering 24 months credit monitoring and identity protection

Sources: Startup Fortune AI Web Searched, The Register Web Search

7.5 Data breach costs hit record $4.99 million in 2026 amid AI-driven attacks

The average cost of a data breach reached a record $4.99 million in 2026, up 10% from 2025, according to the Ponemon Institute's IBM Cost of a Data Breach Report covering over 600 organizations. AI-driven breaches cost approximately $1 million more than non-AI attacks; healthcare remained the costliest industry for the 13th consecutive year, while US organizations paid more than twice the global average.

  • Average breach cost: $4.99 million in 2026 (10% increase from 2025)
  • AI-driven breaches cost ~$1 million more than non-AI attacks
  • Healthcare costliest for 13th consecutive year; US costs 2x global average
  • Detection, escalation, lost business drove cost increases
  • Organizations with AI/automation in security closed breaches 2 months faster, paid ~$2 million less
  • Model inversion attacks costliest AI-specific incidents at $6.07 million average

Sources: Help Net Security AI Web Searched

7.5 MiniOrange SAML Plugin Flaws Exploited to Gain WordPress Admin Access

Attackers are exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML WordPress plugin to gain administrator access. The flaws stem from improper signature validation in the openssl_verify() function, allowing crafted malformed signatures to bypass verification and grant admin privileges.

  • CVE-2026-61979 (CVSS 8.1): unauthenticated privilege escalation via signature algorithm confusion
  • CVE-2026-15981 (CVSS 9.8): authentication bypass accepting malformed signatures as valid
  • Fixed in Standard edition versions 17.0.5 and 17.0.6 respectively
  • Loose boolean check treats -1 return value from openssl_verify() as successful verification
  • Proof-of-concept code publicly available; six IP addresses recorded scanning for vulnerable sites

Sources: The Hacker News AI Web Searched

Cybersecurity

7.5 U.S. sanctions Iranian cyber actors; UK discloses power plant cyber intrusion

The U.S. Treasury sanctioned at least six Iranian nationals on August 24 for breaches of federal agency and UN email accounts, part of a Ministry of Intelligence and Security hacking group active since 2023. Concurrently, the UK disclosed a four-day cyber intrusion on a small British power plant with no reported grid impact.

  • U.S. sanctioned 6 Iranian nationals; 4 indicted for breaches of DoL, FERC, UN accounts
  • Iranian group active since 2023; compromised US federal/state offices in summer 2024
  • UK power plant cyber intrusion lasted 4 days; no power loss or grid impact reported
  • FBI and NSA warned prior Wednesday of attackers targeting programmable logic controllers (PLCs)
  • Nozomi Networks official characterized power plant attack as 'major escalation' from water utility targeting

Sources: The Record AI Web Searched