Posts Tagged ‘email-security’
FortiMail Zero-Day Vulnerability Exploited in the Wild
A FortiMail zero-day vulnerability, CVE-2026-104286 (CVSS 9.8), lets an unauthenticated attacker write arbitrary files onto Fortinet’s email security appliance with nothing more than crafted web requests. Fortinet confirmed active exploitation on October 1, CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, and fixed releases for the 7.4, 7.6 and 8.0…
Read MoreRevolut Data Breach: Trusted Channel Abuse
A recent Revolut data breach shows how attackers can exploit trust without breaking into a bank’s core infrastructure. By using a compromised Italian government email account to submit fraudulent customer-data requests, attackers reportedly persuaded Revolut staff to disclose sensitive information linked to roughly 680 customers across several European countries. The incident exposed a second problem:…
Read MoreZimbra Command Injection Vulnerability Actively Exploited
A Zimbra command injection vulnerability is under confirmed active exploitation against on-premises mail servers, and CISA’s federal remediation deadline of August 24 has already passed. Tracked as CVE-2026-73570, the flaw lets an unauthenticated attacker execute arbitrary shell commands on any unpatched Zimbra Collaboration Suite instance with SNMP notifications enabled — a configuration many administrators never…
Read More
