Floating servers and cyan data tubes exposing critical cloud vulnerabilities.

Daily Cybersecurity News – August 25, 2026

Oracle WebLogic RCE Actively Exploited in Wild

Critical

What happened

CISA added CVE-2026-21962, a maximum-severity improper access control flaw in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation.

The vulnerability scores CVSS 10.0 and lets an unauthenticated attacker with network access via HTTP gain unauthorized creation, deletion, or modification of critical data, plus full access to accessible data on affected instances. Patches shipped in January 2026, yet GreyNoise and CloudSEK observed ongoing attacks, including against honeypots alongside older WebLogic RCEs such as CVE-2020-14882, CVE-2020-2551, and CVE-2017-10271.

Who is affected

Organizations running Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0.

Federal Civilian Executive Branch agencies face a BOD 26-04 deadline of August 27, 2026. Any internet-exposed WebLogic environments remain high-value targets for opportunistic and targeted actors.

Why it matters

A CVSS 10 unauthenticated flaw that grants critical data access or modification can lead to full compromise of enterprise middleware that often sits in front of sensitive applications and databases.

Active exploitation months after patching shows many organizations still lag on Oracle Fusion Middleware updates, keeping a reliable entry point open for ransomware, data theft, and lateral movement.

How it could have been prevented

Apply the Oracle January 2026 security patches for the affected WebLogic Server Proxy Plug-in and HTTP Server versions immediately.

Restrict network access to management and proxy interfaces, monitor for anomalous HTTP traffic matching known exploit patterns, and hunt for indicators from recent GreyNoise and CloudSEK reports. Federal agencies must remediate by the BOD deadline and verify no prior compromise.

Relevant professional terms

Known Exploited Vulnerabilities (KEV) catalog
A CISA-maintained list of security flaws that are confirmed to be actively used in real attacks, which federal agencies must fix on tight deadlines.
Improper access control
A vulnerability class where the software fails to enforce authorization rules correctly, allowing unauthenticated or unauthorized parties to create, read, modify, or delete protected resources.

274 Zimbra Servers Compromised via CVE-2026-73570

High

What happened

Shadowserver Foundation reported at least 274 internet-facing Zimbra Collaboration Suite instances compromised via CVE-2026-73570, a code injection flaw patched in ZCS v10.1.20 on July 20, 2026.

The vulnerability (CVSS 8.9) affects servers with the optional zimbra-snmp package installed and SNMP notifications enabled. Improper sanitization of untrusted input during SNMP notification processing lets an unauthenticated attacker send crafted SMTP requests that execute arbitrary OS commands as the Zimbra user. Polish CERT flagged in-the-wild use a week earlier; CISA added it to KEV and gave federal agencies three days to remediate and check for compromise.

Who is affected

Organizations running Zimbra Collaboration Suite before 10.1.20 that have zimbra-snmp installed and SNMP notifications turned on.

Shadowserver noted roughly 8200 instances still not updated to the fixed version, though not all expose the non-default configuration. Zimbra is popular with entities wanting on-prem control of email and collaboration data.

Why it matters

Successful exploitation yields remote code execution as the Zimbra user on mail and collaboration servers that hold sensitive communications and often serve as pivots into internal networks.

Both state-sponsored actors and opportunistic criminals have historically abused Zimbra flaws, including as zero-days, making unpatched internet-facing instances high-priority targets for data theft, espionage, or further malware deployment.

How it could have been prevented

Upgrade immediately to Zimbra Collaboration Suite v10.1.20 or later. If upgrade is delayed, disable SNMP notifications or remove the zimbra-snmp package as a temporary mitigation.

Review logs for the indicators shared by Polish CERT, scan for unexpected files or processes running as the Zimbra user, and restrict SMTP and management exposure where possible. Federal agencies must meet the short CISA KEV deadline and perform compromise assessments.

Relevant professional terms

Remote code execution (RCE)
A type of flaw that lets an attacker run their own commands or programs on a target system, often without needing to log in first.
Code injection
An attack technique that inserts malicious code or commands into a program’s input processing path so the application executes attacker-controlled instructions in its own context.

First Car Head Unit Malware Fuels BadBox Botnet

High

What happened

Kaspersky researchers identified what appears to be the first malware purpose-built for car head units, discovered on an Android-powered aftermarket infotainment system from Chinese vendor DoFun.

Attackers exploited a vulnerability in the software-update handling system to compromise the update distribution channel and push stealthy malicious Android apps that act as droppers, loaders, clickers, and reverse-proxy loaders. The malware supports nine commands for ad display, ad fraud, and component downloads; observed activity focused on reverse-proxy modules to enroll devices in a proxy botnet. Links point to the MoYu Group, previously tied to the BadBox botnet.

Who is affected

Owners and fleets using vulnerable DoFun Android aftermarket head units, which are widely deployed in China and other APAC markets.

The broader BadBox ecosystem has already compromised more than 10 million Android devices, mainly TV boxes, and is now expanding delivery into vehicle infotainment.

Why it matters

Vehicle head units sit at the intersection of personal data, location, connected services, and sometimes vehicle networks. Turning them into botnet nodes enables fraud, traffic proxying for other crimes, and potential further lateral movement.

The shift from pre-installed malware on cheap devices to supply-chain-style update abuse on automotive systems shows botnet operators diversifying both targets and infection vectors beyond traditional consumer IoT.

How it could have been prevented

Apply the vendor patch for the update-handling vulnerability on DoFun units as soon as it is available. Prefer head units from vendors with transparent update signing and verified channels.

Segment infotainment networks from critical vehicle buses where possible, monitor for unexpected outbound proxy or ad-related traffic, and treat aftermarket Android automotive devices with the same scrutiny given to other untrusted IoT endpoints.

Relevant professional terms

Botnet
A network of compromised devices controlled remotely by attackers and used for fraud, DDoS, proxying, or other large-scale malicious activity.
Reverse-proxy loader
Malware component that turns an infected device into an intermediary proxy, letting operators route their traffic through the victim to hide origin and abuse the device’s network access.
Source: SecurityWeek

UAT-10147 Uses AI for Server Attacks with SPECTRE Rootkit

High

What happened

Cisco Talos detailed Chinese-speaking cybercrime group UAT-10147 targeting Windows and Linux web servers worldwide in education, media, technology, and gaming sectors, with heavy concentration in Brazil, Bolivia, China, Canada, and Vietnam.

The actors gain initial access at scale by exploiting publicly known vulnerabilities, then automate post-exploitation with open-source tools including Metasploit, ysoserial, PentestGPT, DeepAudit, and privilege-escalation exploits. They deploy web shells, BadIIS, Quasar RAT, Gh0stCringe, and a previously unreported cross-platform implant called SPECTRE that includes EDR bypass and Linux rootkit capabilities. AI tools assist with exploit refinement, reconnaissance, payload generation, validation, and documentation. An exposed directory revealed a target list of roughly 170,000 URLs.

Who is affected

Internet-facing Windows and Linux web servers, especially IIS and other vulnerable web applications, across education, media, technology, and gaming organizations globally.

Primary observed victim geography includes Brazil, Bolivia, China, Canada, and Vietnam, with target lists also heavy on U.S., India, U.K., Germany, and Netherlands destinations.

Why it matters

The combination of mass vulnerability scanning, AI-assisted automation, and multi-platform implants (including a new SPECTRE rootkit with EDR evasion) lets a crime group run SEO fraud and data-theft campaigns at industrial scale.

Persistent access via BadIIS (offered as MaaS to multiple Chinese-speaking actors), scheduled tasks, and rootkits turns routine unpatched web servers into long-term beachheads for fraud and further monetization.

How it could have been prevented

Patch known web-facing vulnerabilities promptly and reduce exposure of management interfaces. Deploy and tune EDR/XDR with attention to living-off-the-land binaries, certutil abuse, unusual scheduled tasks (e.g., masquerading as browser updates), and web-shell indicators.

Monitor for BadIIS, Quasar RAT, Gh0stCringe, and anomalous privilege-escalation tool usage; segment web servers; and review logs for outbound connections to known actor infrastructure.

Relevant professional terms

Web shell
A small malicious script planted on a compromised web server that gives attackers remote command execution and file control through ordinary HTTP requests.
EDR bypass
Techniques used by malware or operators to evade or disable endpoint detection and response agents so that malicious activity remains invisible to security tools.

HOL Guard Open-Source AV Protects AI Agents

Low

How it works

  • Intercepts agent actions before execution on the local host
  • Applies mode-specific rules (Gentle / Balanced / Strict / Paranoid)
  • Parses command structure, wrappers, pipelines, redirects, and embedded commands
  • Checks executable provenance, sensitive-path access, network destinations, and bypass attempts
  • Pauses for user approval on risky operations; typical decision under 50 ms
  • Fully local, offline-capable, no file upload

What happened

HOL released HOL Guard, a free open-source tool that sits between AI coding assistants (Claude Code, Cursor, Codex, Gemini CLI, OpenCode, Hermes, OpenClaw, and similar) and the local machine.

When the agent attempts risky actions, the tool pauses execution and prompts the user. It installs in about a minute, runs entirely locally with checks typically under 50 ms, never uploads files, and works offline. Four modes (Gentle, Balanced, Strict, Paranoid) control sensitivity; Balanced is default and focuses on secrets/exfiltration, destructive or encoded execution, prompt injection, dangerous MCP calls, malicious skills, persistence, network egress, and self-bypass attempts.

Who is affected

Developers and operators using local AI coding agents and CLI tools that can execute commands, access files, or call external tool servers.

Anyone running agentic workflows with elevated or broad filesystem and network privileges benefits from an independent mediation layer.

Why it matters

AI agents can be steered by prompt injection or malicious skills into deleting data, exfiltrating secrets, installing persistence, or running untrusted code. A local, low-latency gate that requires human confirmation on high-risk actions reduces blast radius without forcing every operation through a cloud service.

Open detection logic and behavioral parsing of command structure, provenance, sensitive paths, and bypass attempts make the control transparent and auditable.

Relevant professional terms

Prompt injection
A technique that tricks an AI system into ignoring its original instructions by hiding malicious directives inside user input or external content it processes.
MCP calls
Invocations of Model Context Protocol tool servers that let an AI agent reach external functions, files, or services; risky calls can expand the agent’s effective privileges.

9000+ Leaked Active AWS Keys Found in Public Repos

High

What happened

Truffle Security scanners identified 64,024 unique AWS key pairs across public git history, Hugging Face datasets, Docker images, package registries, and CI logs. Of 10,616 pairs with complete credentials that were re-verified, 88 percent still authenticated, totaling more than 9300 live keys.

Among them were 768 corporate keys with full admin rights. Hugging Face was the largest single source (8482 unique live keys across 3394 public datasets, 18 percent with root privileges). Median age of dated keys was about five years; the oldest exceeded 17 years. Only 13.7 percent of enumerable users had a newer key alongside the leaked one, and just 9.5 percent of accounts had any budget alert configured.

Who is affected

AWS account holders whose access keys were committed to public repositories, datasets, container images, packages, or CI logs between 2022 and 2026 and never rotated or revoked.

Both individual developers and corporate accounts are exposed; root and full-admin keys pose the highest immediate risk of account takeover.

Why it matters

Active AWS keys, especially those with admin or root privileges, enable data theft or deletion, resource hijacking, and covert cryptocurrency mining. Long-lived unrotated keys and missing budget alarms mean compromise can persist undetected for years and generate large bills or data loss before anyone notices.

Repeated exposure of the same keys across multiple public artifacts shows secrets once leaked rarely get fully cleaned up.

How it could have been prevented

Immediately delete or rotate any root access keys and long-lived IAM access keys; enforce maximum key age policies via aws iam list-access-keys and automation.

Treat every exposed secret as permanently compromised, enable budget alerts (even low thresholds), watch for AWSCompromisedKeyQuarantine policies, scan public artifacts and internal repos continuously with secret scanners, and prefer short-lived credentials or IAM roles over static keys.

Relevant professional terms

Access key
A long-lived credential pair (Access Key ID and Secret Access Key) that programs use to authenticate API calls to a cloud account.
IAM root privileges
Unrestricted administrative rights on an AWS account that bypass normal permission boundaries and can create, modify, or destroy any resource or identity in that account.

US Sanctions Mabna Institute Hackers Tied to Iran

Medium

What it means

Compliance and security teams should immediately screen for the designated Mabna-linked crypto addresses and any wallets with exposure to them. Institutions handling digital assets must also evaluate secondary-sanctions risk under the new Iran sectoral determinations covering digital assets, technology, gold, aviation, and shipping. Historical victims of Mabna university and enterprise campaigns should re-check for lingering access and harden external research and email-facing systems that were previously attractive targets.

What happened

The U.S. Treasury, as part of Operation Economic Outcast announced August 24, sanctioned five individuals linked to the Mabna Institute, a private Iranian hacking-for-hire group. The five are among 17 Mabna members indicted by the Department of Justice on August 18 for long-running cyber-espionage.

Since at least 2013 the group allegedly compromised 144 U.S. universities, 178 foreign universities, at least 42 U.S. private-sector companies, 11 foreign companies, five U.S. government agencies, and at least two NGOs. OFAC designations include 30 cryptocurrency addresses across Bitcoin, Ethereum, and TRON tied to four defendants; blockchain analysis by TRM Labs estimates roughly $16.8 million in those addresses, with the bulk linked to Keyvan Fayaz.

Who is affected

Universities, private companies, government agencies, and NGOs previously targeted by Mabna Institute campaigns, plus cryptocurrency exchanges, financial institutions, and compliance teams that may process related digital-asset flows.

Secondary sanctions risk now extends more broadly to parties dealing with Iranian digital assets, technology, gold, aviation, and shipping sectors.

Why it matters

The actions increase legal and financial pressure on a prolific Iranian cyber-espionage contractor and its money-movement networks. Sectoral determinations expand secondary-sanctions exposure, forcing compliance teams to screen Iranian-linked exchanges, wallets, and counterparties more aggressively or risk losing access to the U.S. financial system.

Public attribution and wallet designations also give defenders concrete indicators for hunting historical and ongoing activity tied to the group.

Relevant professional terms

Sanctions
Government restrictions that freeze assets, bar transactions, and cut targeted people or entities off from the financial system to punish or deter unwanted behavior.
Secondary sanctions
Penalties that can be applied to third parties outside the primary target jurisdiction if they provide significant support or services to sanctioned sectors or actors, thereby extending enforcement reach.