Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

A Critical Zimbra Flaw Allows Malicious Emails to Execute Code Within User Sessions, Leaving Thousands Exposed A recently disclosed vulnerability in the widely-used email server software Zimbra could allow attackers to craft malicious emails that execute code within a user’s session, compromising sensitive information and potentially leading to further attacks. The issue affects all supported … Read more

Fresh ATM Crypto Software Bugs: Jackpot or Bust?

A series of critical vulnerabilities in a widely-used security software has left organizations and ATMs potentially exposed to compromise. The flaws, discovered by researcher Matt Burch, affect CryptoPro Secure Disk, a full-disk encryption (FDE) solution marketed to both corporate and ATM manufacturers. Burch’s findings have sparked debate about the severity of the issues, with Diebold … Read more

Cybercriminals Flock to Healthcare Businesses as Attacks Surge

The healthcare industry has become a prime target for cybercriminals, with attacks surging in the first half of 2026. According to data from technology research firm Comparitech, the number of cyberattacks on healthcare businesses more than doubled compared to the same period last year, while hospitals and clinics saw a modest increase of 14% in … Read more

Former ransomware negotiator gets 4 years for BlackCat attacks

A former employee of a cybersecurity incident response company has been sentenced to four years in prison for his role in orchestrating BlackCat (ALPHV) ransomware attacks against U.S. companies, collecting an estimated $300 million in ransom payments from over 1,000 victims between November 2021 and September 2023. Angelo Martino, a 41-year-old former employee of DigitalMint, … Read more

Zimbra urges customers to patch critical web client XSS flaw

**Critical Web Client Vulnerability Hits Zimbra Users** Zimbra, a popular email and collaboration software suite used by hundreds of millions worldwide, is urging its customers to patch a critical vulnerability affecting its Classic Web Client. The flaw, which has yet to receive a CVE ID, allows attackers to steal sensitive information through specially crafted emails … Read more

Jen Ellis: Connecting Cyber Community With Political Machinery

Jen Ellis, a stalwart advocate for security researchers, has made waves in the cybersecurity community with her tireless efforts to reform laws that stifle legitimate research. Her dedication and unyielding spirit have earned her numerous accolades, including a recent honor from the British Crown. Ellis’s journey as a champion of cybersecurity policy began over a … Read more

Zimbra urges customers to patch critical web client XSS flaw

Zimbra’s Classic Web Client Hit by Critical XSS Flaw, Patch Urged for Millions of Users A severe vulnerability has been discovered in Zimbra’s Classic Web Client, a widely used email and collaboration software suite that serves hundreds of millions of people worldwide. The security flaw, which allows attackers to execute malicious code through specially crafted … Read more

The Replicant in Your Directory: AI Agents and the Identity Security Gap

In a growing concern for organizations worldwide, artificial intelligence (AI) agents are exposing a gaping hole in identity security. These non-human entities, which include service accounts, OAuth applications, and machine identities, already outnumber human users by as much as 50 to one in many enterprise environments. The issue lies in the fact that identity security … Read more

Money launderer accused of stealing seized crypto while in prison

A shocking case has emerged in the US, highlighting a brazen attempt to steal government-seized cryptocurrency while an individual was behind bars. Rossen G. Iossifov, a Bulgarian national serving a 121-month prison sentence for helping launder millions stolen from American victims of online fraud, has been charged with stealing $290,000 in seized crypto. Iossifov’s alleged … Read more