Skip to content
[SecurityIntel] 21 Aug | Active Exploitation of Zimbra CVE-2026

[SecurityIntel] 21 Aug | Active Exploitation of Zimbra CVE-2026

Buttondown August 21, 2026

SECURITYINTEL DAILY BRIEF ■ Threat Intel Brief Friday, August 21, 2026 INTEL CONFIDENCE 100% THREAT LEVEL CRITICAL THREAT OF THE DAY Active Exploitation of Zimbra CVE-2026-73570 RCE Vulnerability CRITICAL 5 C2 IPs 72 OTX IOCs 38 ARTICLES ■ ANALYST TLDR Today's threat landscape is dominated by active exploitation of a critical Zimbra RCE vulnerability (CVE-2026-73570) and supply chain compromises targeting the Rust ecosystem via the arrayref crate. Additionally, threat actors are leveraging AI-generated exploit scripts against Siemens S7 PLCs in US critical infrastructure, while Russian and Chinese espionage groups deploy advanced OAuth hijacking and AI-assisted malware. ■ CRITICAL STORIES CRITICAL #1 AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure Threat actors are utilizing AI-generated scripts to target operational technology (OT) in critical infrastructure, lowering the technical barrier for sophisticated industrial control system attacks. INFO #2 Hackers poison arrayref Rust crate to push infostealer malware A compromised developer account allowed attackers to inject build-time malware into a widely used Rust dependency, executing malicious payloads on developer workstations during compilation. CRITICAL #3 Critical Zimbra RCE flaw now actively exploited in attacks Attackers are actively exploiting CVE-2026-73570, an SNMP-related remote code execution vulnerability in Zimbra Collaboration Suite, requiring immediate patching. INFO #4 Citrix urges admins to patch new NetScaler flaws as soon as possible Critical authentication bypass vulnerabilities in NetScaler ADC and Gateway allow remote attackers to compromise secure access gateways. ■ CVEs IDENTIFIED CVE-2026-73570 Zimbra Collaboration Suite (ZCS) — Remote Code Execution (RCE) via SNMP Critical (8.9) [CVE-TBD] Elementor Pro WordPress Plugin — Remote Code Execution via file upload Critical [CVE-TBD] isolated-vm — Sandbox escape to host for RCE Critical [CVE-TBD] Citrix NetScaler ADC / Gateway — Authentication bypass Critical ■ THREAT ACTORS Suspected Russian Hackers Nation-State Espionage Abusing Google OAuth and WhatsApp linking to hijack accounts of European targets SilkParasite Nation-State Espionage (China) Targeting Central Asian governments using AI-assisted malware Operation CameraSwarm Actors Cybercriminals / Hacktivists Hacking 14,000 Dahua IP cameras in Ukraine and Russia ■ ATT&CK TTPs T1195.002 Supply Chain Compromise: Compromised Software Dependency | Malicious code injected into the Rust 'arrayref' crate T1203 Exploitation for Client Execution | Build scripts in malicious Rust crates executing payloads during compilation T1190 Exploit Public-Facing Application | Active exploitation of Zimbra CVE-2026-73570 and NetScaler bypasses T1556 Modify Authentication Process | Russian actors abusing Google OAuth and WhatsApp linking to hijack accounts T1110.003 Brute Force: Password Spraying | Microsoft Entra/Graph logs analyzed for password spray attempts T1205 Traffic Signaling | Manic Android malware using nearby infected devices for fallback exfiltration ■ PATCH PRIORITY [P1 PATCH NOW] ≤24h Zimbra Collaboration Suite — Active exploitation of CVE-2026-73570 RCE — CERT Polska [P1 PATCH NOW] ≤24h Citrix NetScaler ADC & Gateway — Critical authentication bypass vulnerability — Citrix [P1 PATCH NOW] ≤24h Elementor Pro — Critical file upload bug allowing RCE — BleepingComputer [P1 PATCH NOW] ≤24h MLflow — Actively exploited flaw leading to cloud credential theft — CISA ■ RECOMMENDED ACTIONS TODAY 1 [P1] Patch Zimbra Collaboration Suite immediately to resolve CVE-2026-73570 to prevent active RCE exploitation. 2 [P1] Apply security updates to Citrix NetScaler ADC and Gateway to remediate the critical authentication bypass vulnerability. 3 [P1] Audit all Rust project dependencies and remove compromised versions of the arrayref crate to block build-time malware execution. 4 [P2] Update Elementor Pro WordPress plugins to the latest version to mitigate file upload vulnerabilities leading to RCE. 5 [P2] Apply patches for MLflow platforms as warned by CISA to prevent unauthorized cloud credential theft. LIVE IOC FEED C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 PORT 8080 STATUS OFFLINE MALWARE Emotet COUNTRY US IP ADDRESS 50.16.16.211 PORT 443 STATUS ONLINE MALWARE QakBot COUNTRY US IP ADDRESS 34.204.119.63 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY US IP ADDRESS 178.62.3.223 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY GB IP ADDRESS 27.133.154.218 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY JP FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

SECURITYINTEL DAILY BRIEF

Friday, August 21, 2026

INTEL CONFIDENCE 100%

Active Exploitation of Zimbra CVE-2026-73570 RCE Vulnerability

Today's threat landscape is dominated by active exploitation of a critical Zimbra RCE vulnerability (CVE-2026-73570) and supply chain compromises targeting the Rust ecosystem via the arrayref crate. Additionally, threat actors are leveraging AI-generated exploit scripts against Siemens S7 PLCs in US critical infrastructure, while Russian and Chinese espionage groups deploy advanced OAuth hijacking and AI-assisted malware.

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

Threat actors are utilizing AI-generated scripts to target operational technology (OT) in critical infrastructure, lowering the technical barrier for sophisticated industrial control system attacks.

Hackers poison arrayref Rust crate to push infostealer malware

A compromised developer account allowed attackers to inject build-time malware into a widely used Rust dependency, executing malicious payloads on developer workstations during compilation.

Critical Zimbra RCE flaw now actively exploited in attacks

Attackers are actively exploiting CVE-2026-73570, an SNMP-related remote code execution vulnerability in Zimbra Collaboration Suite, requiring immediate patching.

Citrix urges admins to patch new NetScaler flaws as soon as possible

Critical authentication bypass vulnerabilities in NetScaler ADC and Gateway allow remote attackers to compromise secure access gateways.

Zimbra Collaboration Suite (ZCS) — Remote Code Execution (RCE) via SNMP

Elementor Pro WordPress Plugin — Remote Code Execution via file upload

isolated-vm — Sandbox escape to host for RCE

Citrix NetScaler ADC / Gateway — Authentication bypass

Suspected Russian Hackers

Abusing Google OAuth and WhatsApp linking to hijack accounts of European targets

Targeting Central Asian governments using AI-assisted malware

Operation CameraSwarm Actors

Hacking 14,000 Dahua IP cameras in Ukraine and Russia

Zimbra Collaboration Suite — Active exploitation of CVE-2026-73570 RCE — CERT Polska

Citrix NetScaler ADC & Gateway — Critical authentication bypass vulnerability — Citrix

Elementor Pro — Critical file upload bug allowing RCE — BleepingComputer

MLflow — Actively exploited flaw leading to cloud credential theft — CISA

■ RECOMMENDED ACTIONS TODAY

C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools

IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB