微软警告称,黑客正在积极利用Zimbra Collaboration Suite中的严重漏洞CVE-2026-73570进行攻击1。该漏洞允许攻击者在无需身份验证的情况下远程执行操作系统命令,从而窃取电子邮件备份和身份验证凭据1。
Zimbra的维护者Synacor于7月20日发布了补丁,但在随后三周多的时间内未向公众披露此漏洞1。微软在7月28日至8月7日期间发现了两个不同的扫描工具正在进行探测活动1。根据Shadowserver Foundation的数据,至少有274个Zimbra实例已遭入侵1。补丁发布后一周内,受影响的未修补服务器数量约为19,000台,之后逐步下降至约12,000台,目前已降至约10,000台1。
Microsoft has warned that threat actors are actively exploiting a critical vulnerability in Zimbra Collaboration Suite to steal email backups and authentication credentials. 1 The flaw, identified as CVE-2026-73570, permits attackers to execute operating system commands remotely without authentication. 1 Zimbra's maintainer Synacor released a patch on July 20, though the vulnerability remained undisclosed for more than three weeks afterward. 1
The scope of exploitation has been substantial. The Shadowserver Foundation identified 274 compromised Zimbra instances, while affected unpatched servers numbered approximately 19,000 within a week of the patch release, later declining to around 12,000 and subsequently to roughly 10,000 systems. 1 Microsoft detected scanning activity targeting the vulnerability between July 28 and August 7, identifying two distinct scanning tools being deployed by attackers. 1
评论
还没有评论,欢迎留下第一条。