<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 8/25/2026

SHARE

Breaches

Hackers breached over 270 Zimbra servers in ongoing attacks

Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. The ZCS email and collaboration suite is used by hundreds of millions of people and organizations, including thousands of businesses and hundreds of government agencies worldwide. Synacor patched the security flaw (tracked as CVE-2026-73570), which allows unauthenticated attackers to gain code execution remotely. READ MORE...

Hacking

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

Cybersecurity firm ReliaQuest has confirmed being targeted by hackers affiliated with the notorious ShinyHunters group, but claims the impact of the attack was limited. ReliaQuest revealed on August 17 in a post on X that it had been tracking a widespread ShinyHunters phishing campaign involving domains with the 'company.claims' URL pattern. The company also warned that the hacker gang has been expanding its social engineering tactics to include legal team impersonation. READ MORE...

Malware

Foul Language: WordlistLoader Disguises Malware as Ordinary Text

A newly discovered malware loader uses lists of ordinary English words to conceal and reconstruct malicious code, helping a rapidly growing infostealer evade detection before infecting victims. Researchers from Gen Threat Labs recently discovered WordlistLoader, a loader used to infect victims with the Amatera infostealer. As a loader, it exists between the initial infection and the final payload. READ MORE...


Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials

Every time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There's a chance that you have just handed a complete stranger access to your savings. Security researchers at Socket have identified scores of malicious linked Firefox add-ons designed to steal cryptocurrency wallet seed phrases or password details. READ MORE...

Information Security

Browser fingerprint tool shows how easy you are to track using the latest sneaky tricks

If you're curious how easily tech companies can fingerprint your browser and device and potentially single them out from the crowd, a new utility Glassbox will show you. Aside from pinging a public geolocation API, it runs entirely in a user's browser and doesn't ship any info out to the web while acting just like all the various trackers, anti-fraud scripts, and other browser fingerprinting tricks one is likely to encounter online. READ MORE...


Inaudible sounds used to fingerprint browsers catch AliExpress red-handed

Chinese retailer AliExpress has been caught fingerprinting visitors after one of the metrics-an outdated technique that measures inaudible sounds it sends to browsers-impeded a researcher's ability to use his bluetooth headphones. Researcher Matthew Callaghan said he stumbled on the stealthy tracking by mistake. After loading the AliExpress homepage, audio from his phone stopped playing over his multipoint headphones, which accept connections from more than one device at a time. READ MORE...

Exploits/Vulnerabilities

Grok fooled into stealing user chat, location data, and more

A new type of prompt injection attack shows why giving AI assistants access to browsers, code tools, and private data deserves extra caution. AI researchers describe "Cryptographic Context Injection"-an attack that hides malicious instructions inside encrypted data. The AI is then persuaded to decrypt that data using its own code-execution tool. As a result, the AI may treat the resulting text as if it were trustworthy internal information. READ MORE...


You don't want this Sleepwalker backdoor on your Windows machine

Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the malware's 23-instruction language. The commands can do everything from running code directly in memory to moving data off the computer. Malware researcher Dominik Reichel discovered the passive backdoor and detailed Sleepwalker in a technical analysis on Monday. READ MORE...

On This Date

  • ...in 1910, Walden W. Shaw and John D. Hertz forms the Walden W. Shaw Livery Company, which will later become the Yellow Cab Company.
  • ...in 1944, after more than four years of Nazi occupation, Paris is liberated by the U.S. 4th Infantry Division.
  • ...in 1985, New York Mets pitcher Dwight Gooden becomes the youngest 20-game winner in Major League Baseball history.
  • ...in 1989, NASA scientists receive stunning photographs of Neptune and its moons from Voyager 2.