New U-Boot flaws could enable stealthy firmware attacks
2026-07-11T01:23:29Z•eaa940386f384aed982afee726865ef081b5bb47fccc81e730921c2541e0babd
active-exploitationai-assisted-attacksaitm,mfa-abuseauth-bypassbootloadercryptocurrencydockerfirmwareforg365giteahelixinjective-sdknpmpersistencephaaSphishingprogress-softwaresharefilestorage-zone-controllersupply-chainu-bootvishingwallet-stealerxsszimbra
What happened
Multiple high-impact security stories: six U-Boot bootloader flaws that could enable stealthy, persistent firmware attacks; an actively exploited critical authentication-bypass in the official Gitea Docker image allowing full user/admin impersonation; and Progress urging ShareFile Storage Zone Controller customers to shut down servers due to a “credible” external threat. Other notable items include a critical XSS in Zimbra's Classic Web Client, an npm supply-chain compromise of the Injective SDK that steals crypto wallet keys, the emergence of new phishing/data-theft operations (Forg365, Helix
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- eaa940386f384aed982afee726865ef081b5bb47fccc81e730921c2541e0babd
- Enrichment time
- 2026-07-11T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.