View all sources for this day →

The Signal

Today’s most consequential items show compromise paths crossing familiar operational boundaries: an internet-facing collaboration server, developer search and terminal workflows, and a public web application reaching database-resident execution. The employee identity incident separately shows why confirmed access should be distinguished from a threat actor’s broader public claim. [1][2][3][4]

Must Know

Zimbra exploitation reporting

Vulnerability · Exploitation

What happened

At least 274 internet-facing Zimbra Collaboration Suite instances were compromised by unknown attackers via CVE-2026-73570, according to the Shadowserver Foundation. [1]

CVE-2026-73570 is a code-injection flaw that Synacor patched in ZCS version 10.1.20, released on July 20, 2026. [1]

Why it matters

The reported compromises involved internet-facing, unpatched Zimbra servers. [1]

Fake Codex advertisements delivering macOS malware

AI & Agents · Incident

What happened

A campaign uses sponsored Google results and fake OpenAI-branded Codex download pages to target Mac developers with malware disguised as installation commands. [2]

The fake page instructs users to paste a Terminal command that appears to install Codex but also decodes an encoded URL, downloads an attacker-controlled shell script, and pipes it into zsh. [2]

Why it matters

Cato reported that the final binaries are universal Mach-O files capable of running natively on Intel and Apple Silicon Macs. [2]

Developer-facing branding and a familiar installation workflow place user judgment at the terminal before later malware analysis, separating the social-engineering decision point from the resulting binary’s platform reach. [2]

Oracle functionality used in an intrusion

Exploitation · Vulnerability

What happened

Huntress reported credential theft after a simple SQL injection in an unnamed organization’s public-facing web app; the attackers then deployed the khunt post-exploitation toolkit through Java stored in an Oracle database. [3]

The attackers sent CREATE JAVA SOURCE commands through Tomcat; Oracle compiled the embedded Java source inside the database as a stored schema object. [3]

Why it matters

Huntress said this database Java-loading technique had rarely been documented in the wild, although it had been discussed previously as oraexec. [3]

The report makes the transition from a public web application to database-resident post-exploitation the key architectural boundary, rather than treating the initial injection as the entire intrusion path. [3]

ReliaQuest employee social-engineering incident

Identity · Incident

What happened

ReliaQuest confirmed that an employee fell for a social-engineering attack, giving attackers a password and brief access to the company’s identity system. [4]

The confirmation followed ShinyHunters’ publication of screenshots on its leak site, where the group claimed a larger compromise. [4]

Why it matters

The incident was preceded by an unusual exchange on X several days earlier, although the supplied evidence does not explain its relevance or outcome. [4]

The confirmation distinguishes the reported brief identity-system access from the leak site’s broader claim, so the latter remains an attributed assertion rather than an established scope. [4]

Also Worth Knowing

Citrix UniconOS recovery capabilities

Platform

What happened

Citrix announced UniconOS dual boot, an endpoint-resiliency capability intended to help organizations recover access to work in minutes without spare hardware, central reimaging, or prolonged business downtime. [5]

Fideo Lens identity and device analysis

Identity · Platform

What happened

Fideo Intelligence introduced Fideo Lens, an investigative intelligence platform for fraud and financial crime teams that helps uncover relationships among identities, accounts, devices and behaviors. [6]

INTERPOL operation against West African crime networks

Security

What happened

INTERPOL’s Operation Jackal IV targeted West African organized crime groups across 22 countries and resulted in 58 arrests and the identification of 263 suspects. [7]

Sources (7)
  1. [1] Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

    helpnetsecurity · August 25, 2026

  2. [2] Crooks push Mac malware through fake OpenAI Codex ads

    theregister security · August 25, 2026

  3. [3] You could've applied all 1,449 Oracle patches and still been hit by this attack

    theregister security · August 25, 2026

  4. [4] ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

    helpnetsecurity · August 25, 2026

  5. [5] Citrix UniconOS dual boot turns Windows endpoints into their own recovery device

    helpnetsecurity · August 25, 2026

  6. [6] Fideo Lens reveals connections across identities, accounts and devices

    helpnetsecurity · August 25, 2026

  7. [7] INTERPOL crackdown on West African crime rings uncovers troubling new trend

    helpnetsecurity · August 25, 2026

Security Daily · August 25, 2026 · Baitaphish