CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Attackers are exploiting CVE-2026-73570 in Zimbra Collaboration, with at least 274 systems identified as compromised. Active attacks also affect JetBrains TeamCity, Metabase, Oracle HTTP Server and Gitea, while U.S. agencies say Medusa ransomware has targeted more than 500 critical-infrastructure organizations.
Zimbra’s flaw permits unauthenticated command injection on vulnerable deployments with zimbra-snmp installed and SNMP notifications enabled. About 12,100 servers were reportedly internet-accessible, although that count may include patched systems and honeypots; Zimbra 10.1.20 provides the permanent fix.
Public proof-of-concept code is available for the TeamCity and Oracle flaws; Metabase’s SQL injection can deliver unauthenticated administrative takeover. Internet-facing instances warrant priority patching and compromise review, especially as Medusa operators have reportedly exploited vulnerabilities before public disclosure.
Editorial: Recommended Actions
01
PRIORITY
Upgrade Zimbra Collaboration to 10.1.20 immediately and investigate exposed systems for compromise. CVE-2026-73570 enables unauthenticated command injection and is actively exploited; at least 274 systems were identified as compromised, while more than 12,100 instances were reportedly internet-accessible.
02
PRIORITY
Apply JetBrains’ patch for CVE-2026-63077 to every TeamCity On-Premises deployment without delay. Unauthenticated attackers can execute operating-system commands, exploitation is active against Australian systems, and public proof-of-concept code lowers the barrier for additional attacks.
03
PRIORITY
Patch Metabase deployments against CVE-2026-72898 immediately and assess pre-patch exposure for unauthorized access. The SQL-injection flaw permits unauthenticated administrative takeover, appears in CISA’s KEV catalog, and several organizations reportedly disclosed unauthorized customer-data access.
04
PRIORITY
Upgrade Gitea 1.17 through 1.27.0 to version 1.27.1 immediately. Attackers can install malicious Git hooks and execute commands as the Gitea service account; CISA lists CVE-2026-60004 in KEV, and one reported attack deployed a cryptocurrency-miner-like payload.
05
PRIORITY
Use the FBI, CISA, and HHS Medusa indicators, TTPs, and mitigations to hunt for intrusion activity and close identified gaps. Medusa has targeted more than 500 critical-infrastructure organizations, reportedly exploited vulnerabilities before public disclosure, and a CareCloud breach exposed sensitive information belonging to nearly four million patients.
ROUNDTABLE
Expert Panel Discussion
12 AI experts analyzed this briefing across 3 turns of structured debate
12Agents16Messages30mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_