Threat Brief — 2026-08-21 — CISA confirms Zimbra in the wild
Active exploitation of a Zimbra Collaboration Suite OS command injection flaw has been formally added to CISA's KEV Catalog, escalating urgency for patching. Separately, fourteen trojanized npm packages are delivering an AI-powered Linux backdoor (RedC2 4.0), and a new SynkLoader malware family is targeting credentials through Microsoft Teams phishing. OWASP also released a new top-10 list and "Universal Skill Format" aimed at securing AI add-ons.
Top items
- Zimbra Collaboration Suite RCE added to CISA KEV (developing). CISA has formally added CVE-2026-73570KEV (ZCS OS Command Injection) to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. This vulnerability was first reported on 2026-08-20 by BleepingComputer; the KEV listing is a new development. Federal agencies and any organization running ZCS should treat patching as time-critical. (src: CISA)
- 14 trojanized npm packages deliver AI-assisted RedC2 4.0 Linux backdoor. Disguised as calendar and streak-tracking utilities, these packages stealthily install a Linux implant that uses AI to assist its command-and-control operations. This extends the ongoing supply-chain attack trend into the npm ecosystem with an AI-enhanced payload. Affected: npm package consumers, Linux endpoints. (src: The Hacker News)
- SynkLoader malware distributed via Microsoft Teams phishing. A previously unknown malware family uses Teams phishing lures to deploy a fake lock screen that harvests credentials. The use of Teams as a delivery channel reinforces the need for tightening external messaging controls. Affected: Microsoft Teams users, credential stores. (src: BleepingComputer)
- OWASP releases top-10 AI skill security blueprint with Universal Skill Format. OWASP has published a new top-10 risk list specifically for AI agent "skills" (add-ons/plugins), debuting a Universal Skill Format to standardize security metadata. This is a defensive framework worth tracking for teams building or consuming AI agent integrations. (src: Dark Reading)
Themes
AI on both sides of the fence. RedC2 4.0's AI-assisted command-and-control and OWASP's new AI-skill security blueprint illustrate the dual trajectory: adversaries are embedding AI into offensive tooling while defenders are racing to standardize security for AI integrations. Teams building AI agents should review the OWASP blueprint against their own skill/plugin architecture.
Supply-chain pressure persists. Trojanized npm packages join recent Rust crate and Firefox extension supply-chain incidents, reinforcing that package ecosystems remain a high-yield attack surface. Verify package provenance and monitor for unexpected post-install behavior.
