AUTO-UPDATED

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited

Recent cybersecurity reports highlight a surge in active exploits targeting Zimbra, Gitea, and Citrix NetScaler, alongside significant data breaches at Manchester Airports Group and Boston Scientific.

Key Points

  • The Shadowserver Foundation identified 274 internet-facing Zimbra instances compromised via the CVE-2026-73570 vulnerability.
  • CISA added the critical Gitea code injection flaw (CVE-2026-60004) and a previously patched Citrix NetScaler vulnerability (CVE-2026-8452) to its Known Exploited Vulnerabilities catalog.
  • Manchester Airports Group confirmed a data breach affecting millions of customers, while Boston Scientific reported a global network outage following a cyberattack.
  • FBI and Justice Department officials successfully dismantled a China-linked hacking network that targeted U.S. government agencies, including NASA and the DOJ.
  • Kaspersky discovered Android malware infecting car head units through software updaters to facilitate ad fraud and proxy botnet operations.

Why it Matters

These incidents demonstrate that attackers are increasingly leveraging both unpatched software vulnerabilities and supply chain weaknesses to disrupt critical infrastructure and global enterprises. Organizations must prioritize rapid patch management and robust logging strategies to mitigate the rising frequency of sophisticated, large-scale cyberattacks.
Help Net Security Published by Anamarija Pogorelec
Read original