← Back
VulnerabilityCybersecurity Dive·3 hours ago

CISA orders agencies to fix exploited Zimbra vulnerability

CISA has ordered federal agencies to remediate an exploited vulnerability in Zimbra collaboration software. The vendor delayed patching the flaw for nearly a month following its initial disclosure, creating an extended window of exposure for affected organizations.

Read full article at Cybersecurity Dive

Related Articles

VulnerabilitySANS Internet Storm Center·3 hours ago

Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)

Attackers can obfuscate IP addresses by using hostnames to bypass security filters that target specific IP strings, a technique particularly relevant for exploiting SSRF vulnerabilities against cloud metadata services. Since most software accepts both IP addresses and hostnames interchangeably, filtering based solely on IP strings like 169.254.169.254 can be circumvented by resolving the equivalent hostname instead. Security teams should implement filtering strategies that account for hostname resolution rather than relying only on IP-based blocklists.

VulnerabilityThe Hacker News·4 hours ago

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Oasis Security discovered a vulnerability in NVIDIA NemoClaw that enables an attacker-controlled webpage to gain unauthenticated access to a local Ollama instance and inject malicious instructions directly into the AI model. This technique allows adversaries to compromise AI agents by poisoning the underlying model through a web-based attack vector. The vulnerability was disclosed to NVIDIA's Product Security team prior to public release.

VulnerabilitySecurityWeek·5 hours ago

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.