Data & infrastructure
-
Zimbra flaw moves into active exploitation
Attackers are exploiting a Zimbra Collaboration command-injection vulnerability that can allow unauthenticated remote command execution on servers with specific SNMP functionality enabled.
-
Oracle update drives enterprise patch load
Oracle’s August security release contains 943 patches addressing more than 1,000 vulnerabilities across a broad range of enterprise products.
-
Leaked Stripe keys expose merchant accounts
Researchers have validated hundreds of exposed Stripe merchant API keys with access to payment and customer functions, without evidence of a Stripe platform breach.
-
Power Pages exposure linked to 27m records
Researchers have linked a 27-million-record data exposure to publicly readable Microsoft Power Pages and Dataverse configurations rather than a confirmed zero-day.
-
Alation investigates unauthorised access
Enterprise data platform Alation is investigating unauthorised activity in one of its systems, with the extent of any customer or data impact still unknown.
-
OpenSSL puts post-quantum transition centre stage
OpenSSL’s October conference in Prague will focus attention on post-quantum migration, cryptographic regulation and the maintenance of critical open-source infrastructure.
-
Four exploited vulnerabilities CISOs should check — now
Four vulnerabilities affecting Microsoft, VMware, and Apple products are now listed by CISA as actively exploited, putting patch status, internet exposure, and the role of affected systems under renewed scrutiny.
-
Clop-linked web shell targets Windchill data
A purpose-built web shell targeting PTC Windchill can decrypt stored credentials, map engineering repositories, and run additional code while operating inside the application’s own trust boundary.
-
Ray flaw moves into active exploitation
CISA has added a critical Ray code-injection flaw to its exploited-vulnerability catalogue after evidence of real-world attacks against the distributed computing framework.
-
NETSCOUT pushes DDoS defence to source
NETSCOUT is extending DDoS mitigation into service-provider networks so compromised subscriber devices can be suppressed closer to the source before attack traffic reaches wider internet infrastructure.










