Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Portable Computer is Perplexity’s new local AI agent – why it’s a game changer

    August 25, 2026

    WhatsApp adds stronger two-step verification, multiple passkeys

    August 25, 2026

    CoinShares buyback authority: Why 25% may not cut shares

    August 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Portable Computer is Perplexity’s new local AI agent – why it’s a game changer
    • WhatsApp adds stronger two-step verification, multiple passkeys
    • CoinShares buyback authority: Why 25% may not cut shares
    • Shingles vaccine linked to 24% lower dementia risk
    • Cambodia targets online wildlife trade on social media, but experts say it’s not enough
    • Sea Lion roars into Falklands expansion as Navitas reels in second FPSO
    • Everything You Always Wanted to Know About IR Grad School
    • Video compilation of police tackling ‘scooter thieves’ is fake – Full Fact
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers breached over 270 Zimbra servers in ongoing attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 25, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.

    The ZCS email and collaboration suite is used by hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies worldwide.

    Synacor patched the security flaw (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, with the release of ZCS version 10.1.20 on July 20.

    image

    CERT Polska, the Polish Computer Emergency Response Team (CERT), first flagged the vulnerability as targeted in the wild last Monday, when it also warned security teams to check their logs for suspicious activity, including the Zimbra service restarting unexpectedly, and for files created in the /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ folders by user zimbra over the last 30 days.

    The Cybersecurity and Infrastructure Security Agency (CISA) also added the flaw to its KEV catalog following CERT Polska’s warning and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to patch their systems within three days, by August 24.

    On Monday, threat security watchdog Shadowserver reported that it spotted hundreds of Internet-exposed Zimbra instances that have already been breached in attacks exploiting the CVE-2026-73570 flaw.

    Map of compromised Zimbra instances
    Map of compromised Zimbra instances (Shadowserver)

    “Zimbra compromises associated with CVE-2026-73570 exploitation are spreading. 274 instances seen compromised in our scans for exploitation artifacts on 2026-08-22,” Shadowserver warned.

    “We also see at least 8200 CVE-2026-73570 unpatched instances (this does not mean exploitable as the vuln is in a non default config).”

    Zimbra vulnerabilities are often targeted by cybercriminals and state-sponsored hacking groups, and have been frequently exploited to steal emails containing sensitive data from vulnerable servers in recent years.

    Most recently, in March, Seqrite Labs researchers spotted APT28 Russian military intelligence hackers abusing a stored cross-site scripting (XSS) Zimbra vulnerability to breach Ukrainian government servers.

    U.S. and UK cyber agencies also warned in October 2024 that Russian Foreign Intelligence Service hackers (tracked as APT29, Midnight Blizzard, and Cozy Bear) compromised Zimbra servers using a ZCS flaw previously exploited to steal email account credentials.

    Russian Winter Vivern cyber spies also exploited a reflected Cross-Site Scripting (XSS) vulnerability to steal emails from NATO-aligned email accounts in attacks targeting Zimbra webmail portals.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    attacks breached hackers ongoing Servers Zimbra
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    WhatsApp adds stronger two-step verification, multiple passkeys

    Police arrests dozens of suspects in global cybercrime crackdown

    South Korean startup platform breach exposes key management failures

    CISA Warns of Exploited Oracle WebLogic Vulnerability

    TikTok reaches $400M settlement with US over COPPA violations

    Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Portable Computer is Perplexity’s new local AI agent – why it’s a game changer

    August 25, 2026

    WhatsApp adds stronger two-step verification, multiple passkeys

    August 25, 2026

    CoinShares buyback authority: Why 25% may not cut shares

    August 25, 2026

    Shingles vaccine linked to 24% lower dementia risk

    August 25, 2026
    Latest Posts

    Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

    July 29, 2026

    Inside the rogue ChatGPT hack of Hugging Face

    July 29, 2026

    ECB wage tracker at 2.7% in Q1 2027, indicating stable negotiated wage pressures

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Portable Computer is Perplexity’s new local AI agent – why it’s a game changer

    August 25, 2026

    WhatsApp adds stronger two-step verification, multiple passkeys

    August 25, 2026

    CoinShares buyback authority: Why 25% may not cut shares

    August 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.