
Opening One Email Can Hand Over Your Zimbra Mailbox
Zimbra patched a critical stored XSS in its Classic Web Client that lets a crafted email run code in your session. Google TAG reported it. Upgrade to ZCS 10.1.19.

Zimbra patched a critical stored XSS in its Classic Web Client that lets a crafted email run code in your session. Google TAG reported it. Upgrade to ZCS 10.1.19.

On Jul 8 2026 a trusted contributor's account pushed a backdoor into 18 npm packages through Injective Labs' own OIDC pipeline. Here is what owners should check.

Progress Software told ShareFile customers to physically shut down on-prem Storage Zone Controllers over a credible threat. No patch, no CVE. What owners should learn.

Microsoft shipped an out-of-band patch for RoguePlanet (CVE-2026-50656), a flaw in the Windows Defender scanning engine that lets a local user climb to SYSTEM on Windows 10 and 11. Because the fix ships through Defender's own silent engine update, the task is to verify the build, not assume the antivirus has you covered.

A flaw nicknamed XRING lets about 260 bytes of ordinary HTTP/3 traffic crash a web server that uses XQUIC, Alibaba's open-source QUIC library. There is no login required, no malformed packet, and as of 10 July no CVE and no fix. The only defence today is a config line you set yourself.

Cloudflare will move its signatures to ML-DSA now rather than wait for NIST's nine new candidates. For owners, the trust layer is the slow half of post-quantum.

CISA added Langflow, a popular tool for building AI agents, to its must-patch list after attackers exploited a flaw to steal companies' AI and cloud keys. It is the first AI agent platform the agency has ever flagged, and the fix is upgrade plus key rotation, now.

The FortiBleed campaign sniffed credentials from FortiGate firewalls using FortiOS own diagnostic tool, feeding INC Ransom and Lynx. A patched firewall is not enough.

A maximum-severity Adobe ColdFusion flaw, CVE-2026-48282, was attacked within minutes of the technical write-up going public. US agencies must patch by 10 July, and the servers most at risk are the forgotten ones still running Remote Development Services.

CVE-2026-53359, named Januscape, is a 16-year-old flaw that lets a rented virtual machine break out and seize the physical host it shares with other tenants. Closing it needs two separate patches, not one, and patched Linux kernels only shipped on 4 July.

CVE-2026-8451 turns a Citrix NetScaler configured as a SAML identity provider into a memory leak that hands attackers live session tokens. Citrix patched it on 30 June 2026 and attacks landed within a day. If your remote access runs on NetScaler, patch and rotate sessions now.

CVE-2026-48558 lets an attacker forge a login token and take over SimpleHelp, the remote tool many IT providers use to run your computers. Around 14,000 servers were exposed, it is on the CISA exploited list, and under NIS2 the reporting duty is yours, not the vendor's.
Page 8 / 11
One considered note on infrastructure, governance, and measurement, most mornings. No theory.