Zero Day Room
Live
Vulnerabilities

CISA warns of exploited Gitea, Citrix flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed in- the-wild exploitation of a critical Gitea vulnerability, CVE-2026-60004, and

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed in- the-wild exploitation of a critical Gitea...

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Tuesday that attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform. The agency added the flaw to its Known Exploited Vulnerabilities (KEV) catalog.

CISA also added a previously patched Citrix NetScaler ADC and Gateway flaw, tracked as CVE-2026-8452, to the KEV catalog, noting it is being exploited in the wild. The agency added six new vulnerabilities to the catalog in total.

Widespread Attacks on Unpatched Systems

Separately, the Shadowserver Foundation reported on Monday that at least 274 internet-facing Zimbra instances have been compromised by unknown attackers. The attacks exploit CVE-2026-73570.

PaperCut Software has identified two vulnerabilities chained in zero-day attacks against its PaperCut NG/MF software. The company has urged users to install a second patch.

Malware and Phishing Campaigns

Kaspersky has discovered a newly discovered Android malware distributed through the built-in updaters in affected Android-based car head units. The malware turns infected devices into ad-fraud tools and nodes in a proxy botnet.

Fortra discovered a phishing method named Chameleon SEO Poisoning. It uses manipulated search results and cloaked fake banking websites to steal credentials while evading security scanners.

Cato Networks uncovered a malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal.

SOCRadar found a phishing-as-a-service (PhaaS) platform called AnonyMousKIT that automates the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones. The service uses AI voice calls.

Supply Chain and State-Sponsored Threats

Two men from Western Australia have been charged after police alleged they were part of TeamPCP, a cybercrime group that planted malicious code in open-source software to break into organizations globally.

The Justice Department and FBI have seized domains tied to two hacking tools built and run by a Chinese state-sponsored group. The malware had been used against U.S. government agencies for years.

Huntress reports that North Korean (DPRK) remote workers are expanding their job searches beyond IT into sales, marketing, and the medical profession.

Incident Disclosures and Research

Medical technology company Boston Scientific suffered a cyberattack that disrupted its IT systems and caused a network outage, affecting global operations.

Manchester Airports Group (MAG) confirmed a breach where someone broke into its systems and stole a quantity of customer data from three UK airports.

Cybersecurity company ReliaQuest confirmed one of its employees fell for a social engineering attack, handing attackers a password and a brief window into the company's identity system.

According to new research from the Cisco-founded AI Workforce Consortium, job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries.

Research from Black Kite indicates mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026.

New Tools and Protections

Google introduced a batch of network security changes coming in Android 17 aimed at making it harder for network operators, snoops, and scammers to track user activity.

HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks the user first. It installs in about a minute, runs on the user's own machine, and a typical check takes under 50 milliseconds.

Proton released AI Paper Trail, a free tool designed to make the information accumulated across AI conversations easier to see.

The source for this overview is Help Net Security's week-in-review for August 30, 2026.

Related coverage

More from Vulnerabilities