Daily Security Intel

Archives
Log in
Subscribe
August 21, 2026

[SecurityIntel] 21 Aug | Active Exploitation of Zimbra CVE-2026-73570 RCE Vulnerability

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Friday, August 21, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Active Exploitation of Zimbra CVE-2026-73570 RCE Vulnerability

CRITICAL

5

C2 IPs

72

OTX IOCs

38

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by active exploitation of a critical Zimbra RCE vulnerability (CVE-2026-73570) and supply chain compromises targeting the Rust ecosystem via the arrayref crate. Additionally, threat actors are leveraging AI-generated exploit scripts against Siemens S7 PLCs in US critical infrastructure, while Russian and Chinese espionage groups deploy advanced OAuth hijacking and AI-assisted malware.

■ CRITICAL STORIES

CRITICAL#1

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

Threat actors are utilizing AI-generated scripts to target operational technology (OT) in critical infrastructure, lowering the technical barrier for sophisticated industrial control system attacks.

INFO#2

Hackers poison arrayref Rust crate to push infostealer malware

A compromised developer account allowed attackers to inject build-time malware into a widely used Rust dependency, executing malicious payloads on developer workstations during compilation.

CRITICAL#3

Critical Zimbra RCE flaw now actively exploited in attacks

Attackers are actively exploiting CVE-2026-73570, an SNMP-related remote code execution vulnerability in Zimbra Collaboration Suite, requiring immediate patching.

INFO#4

Citrix urges admins to patch new NetScaler flaws as soon as possible

Critical authentication bypass vulnerabilities in NetScaler ADC and Gateway allow remote attackers to compromise secure access gateways.

■ CVEs IDENTIFIED

CVE-2026-73570

Zimbra Collaboration Suite (ZCS) — Remote Code Execution (RCE) via SNMP

Critical (8.9)

[CVE-TBD]

Elementor Pro WordPress Plugin — Remote Code Execution via file upload

Critical

[CVE-TBD]

isolated-vm — Sandbox escape to host for RCE

Critical

[CVE-TBD]

Citrix NetScaler ADC / Gateway — Authentication bypass

Critical

■ THREAT ACTORS

Suspected Russian Hackers

Nation-State Espionage

Abusing Google OAuth and WhatsApp linking to hijack accounts of European targets

SilkParasite

Nation-State Espionage (China)

Targeting Central Asian governments using AI-assisted malware

Operation CameraSwarm Actors

Cybercriminals / Hacktivists

Hacking 14,000 Dahua IP cameras in Ukraine and Russia

■ ATT&CK TTPs

T1195.002
Supply Chain Compromise: Compromised Software Dependency | Malicious code injected into the Rust 'arrayref' crate
T1203
Exploitation for Client Execution | Build scripts in malicious Rust crates executing payloads during compilation
T1190
Exploit Public-Facing Application | Active exploitation of Zimbra CVE-2026-73570 and NetScaler bypasses
T1556
Modify Authentication Process | Russian actors abusing Google OAuth and WhatsApp linking to hijack accounts
T1110.003
Brute Force: Password Spraying | Microsoft Entra/Graph logs analyzed for password spray attempts
T1205
Traffic Signaling | Manic Android malware using nearby infected devices for fallback exfiltration

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Zimbra Collaboration Suite — Active exploitation of CVE-2026-73570 RCE — CERT Polska

[P1 PATCH NOW]≤24h

Citrix NetScaler ADC & Gateway — Critical authentication bypass vulnerability — Citrix

[P1 PATCH NOW]≤24h

Elementor Pro — Critical file upload bug allowing RCE — BleepingComputer

[P1 PATCH NOW]≤24h

MLflow — Actively exploited flaw leading to cloud credential theft — CISA

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch Zimbra Collaboration Suite immediately to resolve CVE-2026-73570 to prevent active RCE exploitation.
2[P1] Apply security updates to Citrix NetScaler ADC and Gateway to remediate the critical authentication bypass vulnerability.
3[P1] Audit all Rust project dependencies and remove compromised versions of the arrayref crate to block build-time malware execution.
4[P2] Update Elementor Pro WordPress plugins to the latest version to mitigate file upload vulnerabilities leading to RCE.
5[P2] Apply patches for MLflow platforms as warned by CISA to prevent unauthorized cloud credential theft.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
Older → [SecurityIntel] 20 Aug | AI-Assisted Attacks Target Siemens Critical Infrastructure PLCs
Powered by Buttondown, the easiest way to start and grow your newsletter.