
Daily Cybersecurity News – August 24, 2026
CISA orders urgent patching of actively exploited Zimbra flaw
CriticalWhat happened
CISA has added a Zimbra Collaboration Suite vulnerability to its Known Exploited Vulnerabilities catalog and ordered U.S. Federal Civilian Executive Branch agencies to patch within three days.
The flaw, CVE-2026-73570 (CVSS 8.9), is a command injection issue in the SNMP monitoring component. When the optional zimbra-snmp package is installed and SNMP notifications are enabled, an unauthenticated attacker can send crafted requests that lead to remote code execution as the Zimbra user due to improper input sanitization.
Zimbra patched it in version 10.1.20 (released July 20). CERT Polska first reported active targeting, and Shadowserver observed exploitation artifacts on more than 270 instances.
Who is affected
Organizations running Zimbra Collaboration Suite (ZCS) versions before 10.1.20 with the zimbra-snmp package installed and SNMP notifications enabled.
Shadowserver tracks more than 12,000 Zimbra servers exposed on the internet. ZCS is widely used by governments, businesses, and other organizations worldwide for email and collaboration.
Why it matters
Unauthenticated remote code execution on email and collaboration servers gives attackers a direct path to sensitive communications, credentials, and internal networks.
Zimbra flaws have repeatedly been abused for data theft. Active exploitation plus thousands of internet-facing instances creates immediate risk of widespread compromise, especially for unpatched government and enterprise deployments.
How it could have been prevented
Upgrade immediately to Zimbra Collaboration Suite 10.1.20 or later.
If patching is delayed, disable SNMP notifications and remove or restrict the zimbra-snmp package. Monitor for unexpected Zimbra service restarts and newly created files in /opt/zimbra/jetty/webapps/, /opt/zimbra/jetty_base/webapps/, and /tmp/ owned by the zimbra user. Prioritize internet-facing instances and apply network controls limiting SNMP/SMTP exposure.
Relevant professional terms
- Remote code execution (RCE)
- A vulnerability that lets an attacker run their own commands or programs on a target system from across the network.
- Known Exploited Vulnerabilities (KEV) catalog
- CISA's authoritative list of vulnerabilities confirmed to be under active attack, which triggers mandatory patching deadlines for U.S. federal civilian agencies.
Critical Keycloak Password Reset Flaw Allows Account Takeover
CriticalWhat happened
Red Hat and the Keycloak project released patches for a critical authentication flaw that lets an unauthenticated attacker take over any user account, including administrative ones, by forcing a password reset.
Tracked as CVE-2026-18963 (CVSS 9.1), the issue is improper state validation in the reset-credentials authentication flow (CWE-640). An attacker sends a crafted request to the reset-credentials endpoint; the session jumps straight to the password-update phase without requiring the normal email action token.
No evidence of exploitation in the wild and no public exploit were reported as of the disclosure. Fixed versions include upstream Keycloak 26.7.2 and Red Hat build of Keycloak updates 26.4.15 and 26.6.6.
Who is affected
Deployments of upstream Keycloak prior to 26.7.2 and Red Hat build of Keycloak (RHBK) versions in the 26.4 and 26.6 streams before the listed fixed releases.
Keycloak is a widely used open-source identity and access management server that protects applications and services behind it; successful takeover of admin accounts can cascade to everything relying on it for authentication.
Why it matters
Complete account takeover without user interaction or prior credentials undermines the core trust of an IAM platform. Attackers who control Keycloak identities gain access to connected applications, data, and administrative functions.
Because the flaw requires no authentication and works against any user, the blast radius includes high-privilege accounts and can enable rapid lateral movement or full environment compromise.
How it could have been prevented
Update immediately to Keycloak 26.7.2 (upstream) or the corresponding Red Hat build of Keycloak fixed releases (26.4.15 / 26.6.6 operator and container images).
If immediate patching is not possible, temporarily disable the "Forgot password" functionality as a mitigation. Review authentication logs for anomalous reset-credentials activity and ensure MFA and strong session controls are enforced on critical accounts.
Relevant professional terms
- Account takeover (ATO)
- When an attacker gains full control of a legitimate user account, usually by resetting or stealing credentials.
- Authentication flow state validation
- The server-side checks that ensure a multi-step login or recovery process only advances when prior steps have been properly completed and authorized.
UAT-10147 Uses AI to Scale Server Attacks with SPECTRE and Linux Rootkit
HighWhat happened
Cisco Talos detailed a Chinese-speaking cybercrime group tracked as UAT-10147 that targets Windows and Linux web servers worldwide for SEO fraud and data theft.
The group exploits publicly disclosed vulnerabilities at scale for initial access, then deploys a mix of open-source tools (Metasploit, ysoserial, PentestGPT, DeepAudit) and custom malware. It uses AI-powered tooling to refine exploits, automate post-exploitation, validate payloads, and generate documentation. An exposed directory revealed a target list of roughly 170,000 URLs.
Post-exploitation includes web shells, BadIIS, Quasar RAT, Gh0stCringe, privilege-escalation tools, and a previously unreported cross-platform implant called SPECTRE that includes EDR bypass capabilities, plus a Linux rootkit for persistence. Primary victim geographies include Brazil, Bolivia, China, Canada, and Vietnam, with heavy targeting also noted toward the U.S., India, U.K., Germany, and the Netherlands.
Who is affected
Internet-facing Windows and Linux web servers, especially IIS and other common stacks, in education, media, technology, and gaming sectors.
Organizations with unpatched known vulnerabilities or weak server hardening are exposed. The campaign operates globally with concentration in several countries across the Americas, Asia, and Europe.
Why it matters
The combination of mass scanning, known-vuln exploitation, AI-assisted automation, and multi-platform persistence (including rootkits and EDR bypass) lets a relatively lean operator hit large numbers of servers efficiently.
Compromised web servers become platforms for SEO fraud, data theft, further malware distribution, and long-term access. Builders and operators face both direct data loss and reputational or downstream supply-chain risk if their infrastructure is abused.
How it could have been prevented
Patch internet-facing web servers and applications promptly; prioritize known high-impact RCE and privilege-escalation flaws. Restrict or remove unnecessary services and apply least-privilege configurations.
Deploy EDR/XDR with behavioral detection, monitor for unusual scheduled tasks (e.g., deceptive names like "Google Chrome Start"), certutil abuse, web shells, and unexpected Defender exclusions. Segment servers, enforce strong outbound controls, and hunt for indicators associated with BadIIS, Quasar RAT, Gh0stCringe, and SPECTRE-style implants. Rotate credentials and review access after any suspected compromise.
Relevant professional terms
- Web shell
- A small malicious script planted on a compromised web server that gives an attacker remote command execution through normal web requests.
- EDR bypass
- Techniques used by malware to evade or disable endpoint detection and response tools so that malicious activity goes unnoticed on the host.
Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
HighWhat happened
A financially motivated threat actor tracked by Sublime as Doubloon Dredger has been abusing free Notion accounts, malicious PDFs, and device-code phishing to steal Microsoft authentication tokens.
Attackers create fake executive personas on Notion and send legitimate-looking document-share notifications that pass DKIM, SPF, and DMARC. Victims who click are led through an intermediary PDF containing a "Review and Sign" button that redirects to an EvilTokens phishing page styled as Adobe Acrobat authentication.
The page issues a device code and instructs the user to enter it on Microsoft's real login page, allowing the attacker to obtain an authorization token and access the account. EvilTokens, a phishing-as-a-service platform active since at least February 2026, also supplies a webmail client called MailVault. Related infrastructure showed overlap with Tycoon2FA activity.
Who is affected
Organizations whose users receive and act on Notion share notifications, particularly in manufacturing, telecommunications, retail, health, and logistics.
Any Microsoft 365 or Entra ID environment that still permits device-code authentication is exposed. The campaign relies on users completing the device-code flow after social-engineering lures.
Why it matters
Device-code phishing yields real session tokens that can bypass many traditional password and MFA controls, giving attackers direct mailbox and cloud-resource access.
Abuse of trusted SaaS notification channels (Notion) plus layered PDFs increases deliverability and reduces user suspicion. Token theft enables email compromise, business email compromise fraud, data exfiltration, and further lateral movement inside Microsoft environments.
How it could have been prevented
Disable device-code authentication where business needs allow, or restrict token generation to trusted devices and conditional-access policies.
Train users to treat unexpected document-share or "review and sign" prompts with caution, even from familiar brands, and to verify sharing requests out-of-band. Monitor for anomalous device-code grants, unusual OAuth consent, and token usage from unexpected locations. Implement phishing-resistant MFA and review mail-flow and SaaS application permissions regularly.
Relevant professional terms
- Device code phishing
- A social-engineering technique that tricks a user into entering a code on a legitimate login page, handing the attacker a valid authentication token.
- Phishing-as-a-service (PaaS)
- Ready-made phishing platforms sold to criminals that supply hosting, pages, token capture, and often webmail access so less-skilled actors can run sophisticated campaigns.
Researchers Uncover Thousands of Leaked AWS Keys
HighWhat happened
Truffle Security reported that more than 9,300 leaked AWS access key pairs discovered between August 2022 and August 2026 remain active, including hundreds with full administrative privileges.
Scanners located 64,024 unique AWS key pairs across public sources such as git history, Hugging Face datasets, Docker images, package registries, and CI logs. Of 10,616 complete credential pairs that were re-verified, 88% still authenticated. Among them were 768 corporate keys with full admin rights. Hugging Face was the largest single source (8,482 unique live keys across 3,394 public datasets), and many keys were years old; median age around five years, some over 17 years. Only 13.7% of enumerable keys had been rotated.
The researchers notified identifiable owners and did not publish key material. Only 9.5% of the accounts had budget alerts configured.
Who is affected
Any AWS account whose access keys were committed to public repositories, datasets, container images, or logs and never rotated or revoked.
This includes corporate and personal accounts; one in six leaked keys examined had root privileges. Organizations that embed long-lived keys in code, CI pipelines, or shared artifacts are at particular risk.
Why it matters
Active AWS keys, especially those with admin or root privileges, enable account takeover: data theft or deletion, resource abuse (including cryptomining), persistence, and lateral movement into connected services.
Long-lived, never-rotated keys that remain valid for years turn historical leaks into ongoing liabilities. Lack of budget alerts means costly abuse can go unnoticed, and public exposure across multiple artifact types multiplies discovery chances for attackers.
How it could have been prevented
Immediately delete root access keys from every account (including personal). Inventory IAM access keys with "aws iam list-access-keys", enforce maximum-age policies, and rotate or revoke any key that has ever been exposed.
Treat every publicly observed secret as compromised. Set AWS budget alarms (even low thresholds) to detect unexpected spend such as cryptomining. Prefer short-lived credentials, IAM roles, and OIDC federation over long-lived access keys. Monitor for the AWSCompromisedKeyQuarantine policy attachment, which indicates AWS has detected public exposure. Scan repositories, images, and datasets continuously for secrets before they go public.
Relevant professional terms
- Access key
- A long-lived credential pair (Access Key ID and Secret Access Key) that programs use to authenticate to cloud APIs.
- Secret scanning
- Automated detection of credentials, tokens, and keys inside source code, commit history, containers, and other artifacts to prevent or respond to accidental exposure.