← Back
Data BreachHelp Net Security·3 hours ago

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited

At least 274 internet-facing Zimbra server instances have been compromised through CVE-2026-73570 exploitation, according to the Shadowserver Foundation. The week also saw attackers actively exploiting a previously patched Citrix NetScaler vulnerability, while security researchers highlighted emerging AI supply chain risks appearing in developer workflows.

Read full article at Help Net Security

Related Articles

Data BreachSecurityWeek·23 hours ago

Hasbro Data Breach Exposed Employee Personal Information

Hasbro experienced a cyberattack earlier this year that disrupted operations and has now resulted in a data breach disclosure. The breach exposed personal information belonging to company employees.

Data BreachThe Hacker News·1 day ago

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin's state government has refused to pay extortionists following an August breach of its administrative network, confirming the city as a target of an extortion attempt. Forensic investigations uncovered additional data exfiltration beyond the initial compromise, specifically affecting the Senate Department for Mobility, Transport, Climate Protection and Environment.

Data BreachSecurity Affairs·1 day ago

Love Electric Breach: 877,000 Driver Records Offered for $600

Love Electric, a UK broker managing electric-vehicle salary sacrifice schemes, has allegedly suffered a data breach exposing 877,000 driver records now being offered for sale at $600 on a data-breach forum. The incident underscores identity risks inherent in third-party salary sacrifice providers that handle sensitive personal information as part of employee benefit programs. The breach was first advertised by the seller on August 26 on an English-language forum.

Data BreachThe Hacker News·1 day ago

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

A critical ownCloud vulnerability (CVE-2023-49105) has been added to CISA's Known Exploited Vulnerabilities catalog after a Chinese-speaking threat actor exploited it to breach a Philippine nuclear research organization. The flaw carries a CVSS score of 9.8, indicating severe risk, and is actively being weaponized in the wild. Organizations using ownCloud should prioritize patching this vulnerability immediately.