Security news.
Today's cybersecurity landscape features several critical developments, including urgent patching advisories for actively exploited vulnerabilities in Zimbra and Keycloak, highlighting the ongoing threat of unauthenticated access. Additionally, AI's dual role in both accelerating attacks and offering enhanced security solutions continues to be a prominent theme, with new reports detailing AI-assisted cybercrime and the security challenges posed by AI adoption in development workflows.
CISA Orders Urgent Patching of Actively Exploited Zimbra Flaw
CISA has mandated U.S. government agencies patch an actively exploited OS Command Injection vulnerability (CVE-2026-73570) in Zimbra Collaboration Suite (ZCS) within three days due to evidence of active exploitation.
Critical Keycloak Password Reset Flaw Allows Account Takeover
Red Hat and Keycloak have released patches for a critical flaw (CVE-2026-18963, CVSS 9.1) in their identity and access management server, which could enable unauthenticated attackers to take over any user account via a forced password reset.
91 Vulnerabilities Patched in Spring Application Framework
The Spring Application Framework has addressed 91 vulnerabilities, adding to over 200 patches released this year, significantly more than in previous years, emphasizing continuous security efforts in widely used frameworks.
Operation QUICSILVER Targets Myanmar Government with QUICAgent Backdoor
A cyber espionage campaign, Operation QUICSILVER, is targeting Myanmar's government and IT sectors using graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent, attributed to a China-nexus threat actor.
Iran-Linked Hackers Shut Down UK Power Plant for Four Days
An attack attributed to Iran-linked hackers caused real-world operational disruption by shutting down a UK power plant for four days, raising concerns about the resilience of critical infrastructure.
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
The Chinese-speaking cybercrime group UAT-10147 is leveraging AI to scale attacks on Windows and Linux web servers globally, deploying the sophisticated SPECTRE implant which includes EDR bypass capabilities and a Linux rootkit.
Microsoft August Updates Break Printing, PDF Export in WPF Apps
Microsoft has confirmed that .NET Framework updates from the August 2026 Patch Tuesday are causing issues with printing and PDF export functionalities in WPF applications, impacting user experience.
Personal Information Exposed in Apollo Global Data Breach
Private equity firm Apollo Global has experienced a data breach, exposing personal information, as part of a campaign reportedly targeting major financial companies.