<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Synacor Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Synacor.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers</title><link>https://risky.biz/risky-bulletin-western-cyber-agencies-warn-of-russian-hacks-of-zimbra-servers</link><guid isPermaLink="false">cst-3142</guid><description>Western cybersecurity and intelligence agencies issued a joint warning on Thursday about a Russian hacking campaign targeting Zimbra email servers since at least July 2024. The campaign exploited CVE-2025-66376, a stored XSS vulnerability in the Zimbra webmail client's CSS @import feature, which was patched in November but remains under active attack. The malicious code loads a tool called Ulej to harvest credentials, session tokens, backup two-factor authentication codes, saved passwords, and up to 90 days of email contents.</description><pubDate>Fri, 24 Jul 2026 03:31:32 GMT</pubDate></item><item><title>Russian hackers exploit Zimbra zero-click flaw for email theft</title><link>https://bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft</link><guid isPermaLink="false">cst-3098</guid><description>The Russian state-sponsored group Laundry Bear (also tracked as Void Blizzard) is exploiting a patched Zimbra Collaboration vulnerability alongside phishing attacks to steal email from targeted organizations. CISA has issued a warning about this active exploitation campaign. The vulnerability allows attackers to gain unauthorized access to email systems without user interaction.</description><pubDate>Thu, 23 Jul 2026 16:49:27 GMT</pubDate></item><item><title>March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day</title><link>https://recordedfuture.com/blog/march-2026-cve-landscape</link><guid isPermaLink="false">cst-1981</guid><description>Insikt Group identified 31 high-impact vulnerabilities actively exploited in March 2026, with 29 rated as very critical. The affected products span major vendors including Cisco, Microsoft, Google, ConnectWise, Citrix, and others, with Microsoft and Apple accounting for approximately 32% of the total. Notable findings include the Interlock ransomware group exploiting a Cisco Firewall Management Center zero-day, the continued exploitation of a nine-year-old Hikvision vulnerability, and public proof-of-concept exploits available for 10 of the 31 vulnerabilities.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item></channel></rss>