Latest Internet & Cybersecurity News

đź“…April 25, 2026 at 1:00 AM
Critical vulnerabilities in Zimbra servers, rising AI-fueled cyber threats, botnets targeting infrastructure, and major data breaches dominate global cybersecurity news.
1

Over 10,000 Zimbra Servers Exposed to Persistent XSS Threats

More than 10,500 unpatched Zimbra Collaboration Suite instances worldwide remain vulnerable to CVE-2025-48700, enabling unauthenticated attackers to execute arbitrary JavaScript and access sensitive data.Source 1 Primarily affecting servers in Asia (3,794) and Europe (3,793), CISA added it to its KEV catalog on April 21 due to active exploitation and mandated federal agencies to patch by April 23.Source 1 APT28 exploited a related XSS flaw in phishing attacks on Ukrainian entities.Source 1

2

CISA, FBI Alert on Chinese Volt Typhoon Botnet Targeting Critical Infrastructure

US FBI, CISA, and partners issued a joint advisory on a massive botnet of compromised SOHO routers and IoT devices run by China-linked Volt Typhoon actors.Source 2 The network targets critical infrastructure sectors with covert operations.Source 2 Agencies provided defense recommendations against such threats.Source 2

3

Tennessee Hacker Sentenced for Supreme Court E-Filing Breaches

Nicholas Moore, 25, received 12 months probation after pleading guilty to using stolen credentials to access the US Supreme Court’s e-filing system 25 times, plus AmeriCorps and VA systems.Source 2 He posted screenshots online to impress others rather than for financial gain.Source 2

4

France Titres ANTS Portal Breach Exposes Millions of User Records

A security breach at France's passport and driver’s license agency exposed data of millions, with a threat actor selling 19 million records including names, birth dates, and account IDs on hacking forums.Source 2 The incident affects the ANTS portal.Source 2

5

US Accused of Exploiting Backdoors to Disable Iranian Infrastructure

Iranian media claims US triggered simultaneous failures in Cisco, Juniper, Fortinet, and MikroTik equipment in Isfahan via pre-installed backdoors or supply chain compromises, even when offline.Source 2 Outages occurred during an attack despite disconnection from the internet.Source 2

6

Europe Watchdogs Warn of Escalating Cyber Threats Driven by AI

Europe's securities regulator chief highlighted growing risks and speed of cyberattacks accelerated by AI, echoing financial sector warnings.Source 5 This underscores rising cyber vulnerabilities amid technological advances.Source 5

7

Enterprises in Asia Pacific Face Industrial-Scale Cybercrime

Cybercriminal networks in Asia Pacific operate like enterprises with specialized roles, targeting home routers, endpoints, SaaS, and cloud via coordinated attacks.Source 4 Over 60% of enterprises face IT disruptions from regulations on data privacy, cybersecurity, and AI.Source 4 Defenses must match with intelligence sharing and hygiene.Source 4

8

US Federal Agency Cisco Firewall Infected with Firestarter Backdoor

A US federal agency's Cisco firewall was compromised by the 'Firestarter' backdoor malware, highlighting persistent supply chain risks.Source 2

9

Bitwarden NPM Package Hit in Supply Chain Attack

A Bitwarden NPM package suffered a supply chain attack, potentially exposing users to malicious code in dependencies.Source 2

10

Vulnerabilities Patched in CrowdStrike and Tenable Products

CrowdStrike and Tenable released patches for newly disclosed vulnerabilities in their cybersecurity products.Source 2

11

Locked Shields 2026: 41 Nations Participate in Largest Cyber Exercise

The Locked Shields 2026 exercise saw 41 nations collaborate to bolster cyber resilience against evolving threats.Source 2