Skip to main content
Zimbra

Zimbra

SoftwareWikipedia

Search complete. 50 mentions across 11 episodes found for "Zimbra".

Aug 25, 2026

Dave BittnerHOST
1:24
[background music] Lawmakers request an investigation into cuts at CISA.
Dave BittnerHOST
1:43
Threat actors actively exploit a Zimbra collaboration suite vulnerability.
Dave BittnerHOST
1:48
A Chinese AI lab preps release of a powerful open-weight model.
Dave BittnerHOST
1:52
A new phishing toolkit deploys attacker-controlled passkeys.
Dave BittnerHOST
4:02
Lawmakers are seeking clarity on whether lost expertise has been replaced as threats to critical infrastructure continue to evolve.
Dave BittnerHOST
4:11
The Government Accountability Office confirmed receiving the congressional request and is determining whether to proceed.
Dave BittnerHOST
4:20
Threat actors are actively exploiting a Zimbra collaboration suite vulnerability, with Shadowserver reporting at least two hundred seventy-four compromised instances.
Dave BittnerHOST
4:31
The flaw is a command injection vulnerability in Zimbra's Simple Network Management Protocol monitoring component.
Doug WhiteHOST
0:09
I'm Doug White.
Doug WhiteHOST
0:11
We've got Fibonacci and the unhappy number, Hidden Sounds, Teams, Zimbra, IntraID, ZAI, Schrödinger's battery, Aaron Leyland, and more on the Security Weekly News.
Doug WhiteHOST
0:24
We interrupt this program-
speaker_1UNKNOWN
0:25
-to bring you-
Doug WhiteHOST
4:54
Listeners save thirty percent on their pass with code ISW26-SWsavings at securityweekly.com/infosecworld2026.
Doug WhiteHOST
5:07
All right.
Doug WhiteHOST
5:08
Zimbra.
Doug WhiteHOST
5:09
Uh, Zimbra Collection Suite, or ZCS, as a lot of people call it, is used by, according to them, hundreds of millions of people and thousands and thousands of organizations, and apparently there's a flaw which would allow unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.
James AzarHOST
2:01
Our first story is already urgent enough that the deadline has technically come and gone.
James AzarHOST
2:06
CVE-2026-73570 is a Zimbra collaboration suite flaw involving improper sanitization of untrusted input during SNMP notification processing.
James AzarHOST
2:15
So in plain English...
James AzarHOST
2:17
A specially crafted SMTP request triggers command injections in the SNMP monitoring component.
James AzarHOST
3:03
as of the time we record this shadow server still tracking more than 12 000 zimbra servers still exposed online the fix is zimbra collaboration suite 10.1.20 released back on july 20th which means this was patchable for a full month before exploitation began so if you haven't updated Do it today.
James AzarHOST
3:24
After patching, you should go through your logs.
James AzarHOST
3:26
Look for unexpected Zimbra service restarts and audit file creation over the past 30 days in a slash opt slash Zimbra slash Jetty slash web apps.
James AzarHOST
3:39
Jetty underscore is a base slash web apps and slash TMP.
Doug WhiteHOST
0:09
I'm Doug White.
Doug WhiteHOST
0:11
We've got Fibonacci and the unhappy number, Hidden Sounds, Teams, Zimbra, IntraID, ZAI, Schrodinger's Battery, Aaron Leland, and more on the Security Weekly News.
Doug WhiteHOST
0:26
It's the show that keeps you up to date on the latest security news twice a week.
Doug WhiteHOST
0:30
Your trusted source for accurate security information and expert analysis.
Doug WhiteHOST
4:54
Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com slash InfoSecWorld2026.
Doug WhiteHOST
5:07
All right.
Doug WhiteHOST
5:08
Zimbra.
Doug WhiteHOST
5:09
Zimbra Collection Suite, or ZCS as a lot of people call it, is used by, according to them, hundreds of millions of people and thousands and thousands of organizations.
Doug WhiteHOST
0:09
I'm Doug White.
Doug WhiteHOST
0:11
We've got Fibonacci and the unhappy number, Hidden Sounds, Teams, Zimbra, IntraID, ZAI, Schrodinger's Battery, Aaron Leland, and more on the Security Weekly News.
Doug WhiteHOST
0:26
It's the show that keeps you up to date on the latest security news twice a week.
Doug WhiteHOST
0:30
Your trusted source for accurate security information and expert analysis.
Doug WhiteHOST
4:51
Join us in Orlando, October 12th to 14th.
Doug WhiteHOST
4:54
Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com slash InfoSecWorld2026.
Doug WhiteHOST
5:07
All right, Zimbra.
Doug WhiteHOST
5:09
Zimbra Collection Suite, or ZCS as a lot of people call it, is used by, according to them, hundreds of millions of people and thousands and thousands of organizations, and apparently does a flaw which would allow unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled.
Doug WhiteHOST
0:09
I'm Doug White.
Doug WhiteHOST
0:11
We've got Fibonacci and the unhappy number, Hidden Sounds, Teams, Zimbra, IntraID, ZAI, Schrodinger's Battery, Aaron Leland, and more on the Security Weekly News.
Doug WhiteHOST
0:26
It's the show that keeps you up to date on the latest security news twice a week.
Doug WhiteHOST
0:30
Your trusted source for accurate security information and expert analysis.
Doug WhiteHOST
4:54
Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com slash InfoSecWorld2026.
Doug WhiteHOST
5:07
All right.
Doug WhiteHOST
5:08
Zimbra.
Doug WhiteHOST
5:09
Zimbra Collection Suite, or ZCS as a lot of people call it, is used by, according to them, hundreds of millions of people and thousands and thousands of organizations.
Michael HooshHOST
5:50
Email infrastructure is facing its own set of threats.
Michael HooshHOST
5:54
Unpatched Zimbra servers are currently being targeted by attackers exploiting CVE twenty twenty-six seven three five zero.
Michael HooshHOST
6:02
Zimbra is a widely used email and collaboration platform, and the vulnerability allows unauthorized access with potential for lateral movement inside affected environments.
Michael HooshHOST
6:12
The lesson here is familiar.
Michael HooshHOST
6:14
Patch quickly, monitor for indicators of compromise, and review your email infrastructure for any lingering vulnerabilities.

7 MINS LATER

Michael HooshHOST
13:10
Finally, strategic alliances and advanced security tooling are critical to addressing the scale and complexity of today's threats.
Michael HooshHOST
13:18
Whether it's integrating AI-driven security platforms or leveraging shared threat intelligence, organizations need to think beyond traditional boundaries.
Michael HooshHOST
13:28
So, what matters most today? First and foremost, immediate action is required to patch critical Oracle, Keycloak, and Zimbra vulnerabilities.

Unknown podcast

CXO Daily Cybersecurity Intelligence Brief For Aug. 25, 2026

Aug 25 · 1 Mention

Artie FisherHOST
3:14
NextGov Cybersecurity reports the Treasury Department has launched a public-private task force to prepare finance for quantum-enabled threats, pushing the sector toward adopting quantum-resistant practices.
Artie FisherHOST
3:25
BleepingComputer notes CISA's emergency Zimbra patch mandate, likely accelerating patch cycles beyond government to vendors and partners.
Artie FisherHOST
3:33
GBHackers warns of thousands of WordPress admin accounts at risk due to MiniOrange SAML SSO flaws, a critical issue for organizations with distributed site management.
Artie FisherHOST
3:43
And Cyber Insider flags a governance red flag.
Dave BittnerHOST
5:54
According to Kaspersky, the campaign is attributed with high confidence to MoYu Group, linked to the Bad Box operation.
Dave BittnerHOST
6:04
CISA has ordered federal civilian agencies to patch an actively exploited Zimbra collaboration suite vulnerability immediately.
Dave BittnerHOST
6:13
Today is the deadline.
Dave BittnerHOST
6:15
The command injection flaw affects the Simple Network Management Protocol, or SNMP, notification component when notifications are enabled.
Dave BittnerHOST
6:25
Zimbra patched the issue in a recent version.
Dave BittnerHOST
6:28
CERT Polska first reported active exploitation.
Dave BittnerHOST
6:31
Shadowserver later identified more than two hundred and seventy compromised Zimbra instances while searching for exploitation artifacts.
Dave BittnerHOST
6:40
Successful exploitation can let an unauthenticated attacker execute operating system commands as the Zimbra user.

Unknown podcast

Zimbra Zero-Click RCE, Check Point Bypass, and Device Code Phishing

Aug 24 · 13 Mentions

Mauven MacLeodHOST
0:42
We'll get to it.
Mauven MacLeodHOST
0:43
But we start where the urgency is highest, a zero-click remote code execution floor in Zimbra, with a three-day federal patch deadline from CISA and a Russian-linked threat actor behind the campaign.
Mauven MacLeodHOST
0:56
That deadline tells you something.
Mauven MacLeodHOST
0:58
CISA doesn't issue three-day windows for theoretical risks.
Mauven MacLeodHOST
1:04
CSR added CVE-2025-66376 to its Known Exploited Vulnerabilities Catalogue this week, and as I mentioned, the patch deadline for US federal agencies is three days.
Mauven MacLeodHOST
1:17
We've covered the known exploited vulnerabilities catalog many times on this show, going back to episode two in June, and that three-day window is, every time, the clearest possible signal that exploitation is happening at scale right now, not in a threat model, not in a proof-of-concept lab environment, now, in the wild.
Mauven MacLeodHOST
1:37
The vulnerability itself is a zero-click remote code execution flaw in Zimbra Collaboration Suite.
Mauven MacLeodHOST
1:44
Zero click means no user interaction is required.

1 more episode mentions Zimbra.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.