● On the wire
Ubuntu 24.04 LTS Linux-NVIDIA Kernel Moderate Security Issue USN-8623-1//Debian Incus Significant Privilege Escalation Vulnerabilities DSA-6407-1//ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th)//Securing Embodied AI: A Technical White Paper on Humanoid Robots//Debian Chromium Important Code Execution Denial of Service DSA-6408-1//Ubuntu OpenSSL Critical Denial of Service Issue USN-8625-1//How Federal Agencies Can Turn Year-End Funding Into Long-Term Cyber Capability//Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)//Ubuntu Linux Kernel Important NTFS Out-of-Bounds Read CVE-2023-45896//Cisco Advance Notification for Publication of August 5, 2026, Security Advisories//Ubuntu 26.04 LTS Linux-Nvidia Security Flaws Update USN-8622-1//Debian libgd2 Important Denial of Service CVE-2026-9672//Patch In, Exploit Out: How deepsec Reconstructed the Pwn2Own Microsoft Edge Sandbox Escape//Cisco Secure Firewall Management Center Software Static Credential Vulnerability//LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection//Ubuntu 24.04 LTS Linux-NVIDIA Kernel Moderate Security Issue USN-8623-1//Debian Incus Significant Privilege Escalation Vulnerabilities DSA-6407-1//ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th)//Securing Embodied AI: A Technical White Paper on Humanoid Robots//Debian Chromium Important Code Execution Denial of Service DSA-6408-1//Ubuntu OpenSSL Critical Denial of Service Issue USN-8625-1//How Federal Agencies Can Turn Year-End Funding Into Long-Term Cyber Capability//Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)//Ubuntu Linux Kernel Important NTFS Out-of-Bounds Read CVE-2023-45896//Cisco Advance Notification for Publication of August 5, 2026, Security Advisories//Ubuntu 26.04 LTS Linux-Nvidia Security Flaws Update USN-8622-1//Debian libgd2 Important Denial of Service CVE-2026-9672//Patch In, Exploit Out: How deepsec Reconstructed the Pwn2Own Microsoft Edge Sandbox Escape//Cisco Secure Firewall Management Center Software Static Credential Vulnerability//LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection//
Campagna russa contro Zimbra con exploit zero-click e furto di email e codici 2FA
Top story — News

Russian campaign against Zimbra with zero-click exploit and theft of emails and 2FA codes

Several Russia-linked groups exploited an as-yet-unknown vulnerability in Zimbra for months to target government and strategic organizations in the West. The vector was particularly dangerous because simply opening or even just viewing the email message in the web client was enough to trigger the exploit, with no explicit click required from the user. Once inside, the attackers targeted email inboxes…

Read the article →
From the newsroom
Spotlight
More news