Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7

Progress tells ShareFile customers to shut down file servers over credible threat

Progress Software has told ShareFile customers to immediately shut down the on-premises Windows servers running Storage Zone Controllers, citing a "credible external security threat" against its enterprise file-sharing platform. The company has temporarily disabled access to affected accounts and says it has no sign of unauthorized access yet, but it has not disclosed what the threat is or whether a vulnerability is involved. Ordering a full shutdown rather than a patch strongly suggests there is no fix available. Only self-hosted Storage Zone Controllers, which typically sit internet-facing at the network edge, are affected, not cloud-only ShareFile. Progress also makes MOVEit, whose 2023 zero-day was mass-exploited by the Clop group.

Check
Determine whether you run ShareFile Storage Zone Controllers, and if so, follow Progress's guidance to shut down the hosting Windows servers now, while preserving system and administrative logs for investigation.
Affected
Organizations running on-premises ShareFile Storage Zone Controllers, which broker files between local storage and the ShareFile cloud and are usually internet-facing; cloud-only ShareFile accounts are not affected by this advisory.
Fix
Shut down Storage Zone Controller servers as Progress directs until a fix or all-clear is issued, review recent administrative activity and internet exposure, and watch for Progress updates.

Six U-Boot bootloader flaws could run code before a device checks its firmware

Researchers at Binarly found six flaws in U-Boot, the open-source bootloader inside routers, IoT devices, industrial systems, and the management chips of data-center servers. All six are triggered while U-Boot is still reading an untrusted firmware image, before it verifies the signature, so an attacker who supplies a malicious image can act before the trust check runs. Two of the flaws can lead to arbitrary code execution at boot, undermining the whole chain of trust, while the other four crash the device. The vulnerable code dates back to 2013, affecting many releases and vendor forks. Exploiting them does not always need physical access: a compromised management interface could push a malicious image.

Check
Identify devices built on U-Boot, especially servers with baseboard management controllers and networking or IoT gear, and check with vendors whether firmware updates addressing these flaws are available or planned.
Affected
Devices using U-Boot, including many routers, IoT and industrial systems, and server management controllers; malicious firmware images can crash them or run code at boot before the signature is verified.
Fix
Apply vendor firmware updates as they incorporate the upstream fixes, restrict and monitor access to management interfaces that can push firmware images, and retire devices no longer receiving updates.

Zimbra patches critical flaw letting a crafted email run code in your session

Zimbra is urging customers to update after fixing a critical stored cross-site scripting flaw in the Classic Web Client of its widely used email and collaboration platform. A specially crafted email can run malicious scripts when it is simply opened, potentially exposing mailbox contents, session data, and account settings, and enabling session hijacking or credential theft. The flaw, reported by Google's Threat Analysis Group, has no CVE assigned yet and is not confirmed as exploited, but the group often surfaces bugs used by state-backed actors. Zimbra's web client has been a repeated target: Russian-linked groups have exploited similar cross-site scripting flaws against government and military organizations. Updating to version 10.1.19 fixes it.

Check
Identify Zimbra Collaboration servers using the Classic Web Client, confirm their versions, and prioritize updating any that are internet-facing or serve high-value users such as executives and administrators.
Affected
Organizations running Zimbra Collaboration's Classic Web Client before version 10.1.19; an attacker can run code in a victim's session by sending an email the victim opens, risking mailbox and credential theft.
Fix
Update Zimbra Collaboration to version 10.1.19 promptly, given the platform's history of state-actor exploitation, and consider moving users to the modern web client and monitoring for suspicious email-borne scripts.

Fake Go scanning tool hides malware across 222 GitHub repositories

Researchers at Socket uncovered a network of 222 GitHub repositories, tracked as Operation Muck and Load, built to spread Windows malware through a fake Go module posing as a DNS and subdomain scanner. Running the module quietly launches PowerShell that pulls an encrypted payload from attacker infrastructure and deploys infostealers, remote access trojans, and cryptominers. To look trustworthy, the operators used an automated workflow that force-pushes fake commits every minute, making repositories appear actively maintained and generating hundreds of package versions. More than 700 of the module's 1,200-plus versions were malicious. The lures cluster around crypto wallets, Telegram bots, and game cheats, aimed at people likely to run untrusted code.

Check
Review whether developers pulled Go modules or ran tools from unfamiliar GitHub repositories, particularly crypto, wallet, or game-cheat-themed ones, and watch for hidden PowerShell launching from a supposed utility on developer machines.
Affected
Developers and users who clone, build, or run code from these lure repositories; a module posing as a legitimate scanner instead installs infostealers, remote access trojans, or cryptominers on their Windows machines.
Fix
Verify a repository's authenticity beyond how active it looks, since fake commit activity can be manufactured, prefer official module sources, inspect code before running it, and use isolated environments for untrusted tools.

Exposed server reveals crew that backdoored thousands of WordPress sites for resale

A cybercrime group left its own server exposed on the internet for weeks, revealing a mass website-hacking operation that researchers at SOCRadar now track as WP-SHELLSTORM. The crew breaks into sites at scale, plants hidden backdoors, and resells the access to other criminals. Rather than using zero-days, it automated attacks against 27 known vulnerabilities in outdated WordPress and Joomla plugins; a single flaw in the Breeze caching plugin accounted for over 17,000 backdoored sites. Target lists named more than 1.4 million domains, with roughly 25,000 confirmed compromised. The same server also revealed an earlier campaign that stole cloud credentials and database passwords from exposed configuration servers.

Check
Update WordPress and Joomla plugins, especially the Breeze caching plugin and Joomla's JCE editor, and hunt for webshells with suspicious names and fake kernel-worker processes that indicate a backdoor.
Affected
Organizations running WordPress or Joomla sites with outdated, vulnerable plugins; the crew automatically exploits known flaws to plant backdoors, then sells that access, making even low-profile sites worthwhile footholds.
Fix
Keep plugins patched on a regular cadence, put a web application firewall in front of anything you cannot patch immediately, scan for known webshell indicators, and rotate credentials on exposed configuration servers.

GhostApproval tricks AI coding agents into writing to SSH keys via symlinks

Researchers at Wiz disclosed GhostApproval, a technique that abuses symbolic links to make AI coding assistants write to sensitive files outside the project. A malicious repository includes a symlink named like an innocent file, such as project_settings.json, that actually points to the developer's SSH authorized_keys or shell startup file. When the developer asks the agent to set up the workspace, it follows the link and writes attacker content, such as an SSH key granting passwordless access. The deeper problem is that the approval prompt shows only the harmless filename, not the real target, so the human approves a change they cannot see. Wiz tested six assistants including Claude Code and Cursor.

Check
Confirm your AI coding assistants are updated to versions that resolve symlinks before showing approval prompts, and be cautious running set-up or README instructions from untrusted repositories.
Affected
Developers using AI coding assistants that follow symlinks without showing the real target; a malicious repository can trick the agent into writing SSH keys or shell config outside the project.
Fix
Update coding assistants to fixed versions, review any file write an agent proposes for symlinks and out-of-workspace paths, avoid untrusted repositories' setup instructions, and watch SSH keys and shell config.

AssuranceAmerica breach exposes driver's license data of 6.9 million people

US auto insurer AssuranceAmerica has confirmed a breach affecting nearly 6.9 million people, the largest known exposure of Americans' driver's license data this year. The company detected the intrusion on March 17 after attackers compromised a single employee's credentials the day before and copied data files, but a lengthy review of the files was not finished until June 15, delaying notifications until now. The stolen data includes names, contact details, driver's license numbers, auto insurance policy and claims information, and, for some people, Social Security numbers. AssuranceAmerica has not detailed how the employee's credentials were taken, though such incidents are often tied to phishing or credential-stealing malware.

Check
People insured by AssuranceAmerica should watch for a breach notification, monitor bank and credit accounts and credit reports for fraud, and be wary of messages referencing their policy or claims.
Affected
Roughly 6.9 million AssuranceAmerica customers whose driver's license numbers, contact details, and insurance information were exposed, along with Social Security numbers for some; the data enables identity theft and convincing targeted phishing.
Fix
Affected people should consider a credit freeze given exposed license and Social Security numbers, monitor financial accounts, and treat insurance-themed messages cautiously. Organizations should enforce phishing-resistant MFA on employee accounts.

Compromised Injective npm SDK stole crypto wallet keys from developers' apps

Attackers compromised a legitimate maintainer's GitHub account for the Injective blockchain SDK and used it to push a malicious version of the widely used @injectivelabs/sdk-ts npm package, which has around 50,000 weekly downloads. The tainted code, disguised as usage telemetry, hooked the SDK's wallet key-generation functions to capture private keys and seed phrases, then sent them to a server made to look like legitimate Injective infrastructure. Trusted-publishing automation spread the malicious release across 18 packages within minutes, though it was live under an hour before being pulled. Because the theft can reach apps that used the SDK only indirectly, any wallet keys handled by affected versions should be treated as compromised.

Check
Check whether your projects or dependencies pulled the malicious Injective SDK version, including transitive dependencies and cached copies, and review whether any wallet keys or seed phrases passed through affected code.
Affected
Developers and applications using the affected @injectivelabs/sdk-ts versions, and their users; the malware captured wallet private keys and seed phrases, even for apps that depended on the SDK only indirectly.
Fix
Move any potentially exposed cryptocurrency to fresh wallets, rotate secrets in affected environments, pin dependencies to known-good versions, and protect maintainer accounts and publishing pipelines with phishing-resistant MFA.

Forg365 phishing service uses AI to steal Microsoft 365 accounts and stay in

A new phishing-as-a-service platform called Forg365 is built to steal Microsoft 365 accounts, combining adversary-in-the-middle and device-code phishing with AI-generated lures created directly in its control panel. Researchers at ZeroBEC found the panel lets operators build campaigns, configure malicious OAuth apps, generate and refine phishing emails with AI, and monitor compromised mailboxes for keywords, all in one place. It also ships a browser extension that silently refreshes session cookies through an OAuth flow, giving attackers ongoing access without re-authenticating. The operators deliver lures posing as business documents, using legitimate email-sending infrastructure to slip past filters. The researchers note AI is lowering the cost of both writing phishing content and building phishing platforms.

Check
Hunt for adversary-in-the-middle and device-code phishing against Microsoft 365, review OAuth app consents and unexpected browser extensions, and check for mailbox rules or session tokens giving attackers persistent access.
Affected
Microsoft 365 users targeted by business-document lures; Forg365 captures session tokens to bypass multi-factor authentication and uses a browser extension to keep access alive even after passwords or sessions are reset.
Fix
Enforce phishing-resistant methods like passkeys, apply Conditional Access to limit device-code and token sign-ins, review and restrict OAuth app consents and browser extensions, and monitor for anomalous token use.

GodDamn ransomware uses a Microsoft-signed malicious driver to disable defenses

Symantec detailed GodDamn, a ransomware operation that disables endpoint defenses using PoisonX, a malicious kernel driver its developers managed to get signed by Microsoft, an unusual escalation over the more common tactic of abusing a legitimate vulnerable driver. In an early-June attack, the operators used AnyDesk for remote access and a credential-harvesting toolkit that pulls passwords from browsers, Windows Credential Manager, cached domain credentials, email clients, and network traffic, before deploying the ransomware. Alongside the signed driver, they ran a user-mode tool disguised as a Symantec product to blind security software. Symantec links GodDamn to a developer it tracks as Hyadina and says the group is actively improving its defense-evasion capabilities.

Check
Watch for bring-your-own-driver activity and processes masquerading as security products, audit remote-access tools like AnyDesk in your environment, and monitor for credential-harvesting across browsers and Windows credential stores.
Affected
Windows organizations where attackers gain a foothold; GodDamn uses a Microsoft-signed malicious driver to switch off endpoint defenses, harvests credentials broadly, then encrypts systems, making detection before deployment much harder.
Fix
Enable driver block lists and tamper protection, restrict who can load kernel drivers, tightly control remote-access software, enforce phishing-resistant MFA, and keep monitored offline backups so encryption stays recoverable.