New U-Boot flaws could enable stealthy firmware attacks
2026-07-11T07:23:27Z•d0f3bdebaa0d99bbd056c9b5804296f06363671f6b85e4bd11f8c3c11e42cacc
active-exploitationai-assisted-attacksauth-bypassbootloadercryptocurrency-theftdata-breachdockerfirmwaregiteamalwarenpmodidophaaSphishingransomwareryuksharefilestorage-zone-controllersupply-chainu-bootvishingxsszimbra
What happened
Multiple high-impact security stories: six U-Boot bootloader flaws that can enable stealthy firmware-level attacks; active exploitation of a critical auth-bypass in the official Gitea Docker image allowing full user impersonation; Progress urging immediate shutdown of ShareFile Storage Zone Controller servers over a “credible” external threat; a critical XSS in Zimbra Classic Web Client with patching urged; Injective SDK on npm was compromised to include a cryptocurrency wallet stealer; emergence of Helix vishing group and Forg365 phishing-as-a-service using AiTM/device-code and AI lure-gen; a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d0f3bdebaa0d99bbd056c9b5804296f06363671f6b85e4bd11f8c3c11e42cacc
- Enrichment time
- 2026-07-11T07:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.