Top stories.
- US lawmakers seek investigation into impact of CISA cuts.
- Zimbra servers targeted in ongoing attack campaign.
- US Treasury Department levies sanctions on alleged Iranian hackers.
US lawmakers seek investigation into impact of CISA cuts.
US Congressional Democrats have called for the Government Accountability Office (GAO) to analyze the impacts of staffing cuts at the US Cybersecurity and Infrastructure Security Agency (CISA), the Record reports. Nearly one-third of the agency's workforce was cut at the beginning of President Trump's second term. Bennie Thompson (Democrat of Mississippi) and four other Democrats said in a letter to the GAO, "[W]e respectfully request that the [GAO] examine the impact of recent staffing reductions and programmatic cuts at CISA on the agency's ability to carry out its mission requirements, protect critical infrastructure, and respond to evolving cyber and physical threats."
A GAO spokesperson acknowledged receipt of the request, stating, "GAO has a process it goes through to determine whether we do work and when, which we are working through right now."
Zimbra servers targeted in ongoing attack campaign.
Attackers have compromised more than 270 Zimbra instances by exploiting a high-severity flaw in Zimbra Collaboration Suite (ZCS), BleepingComputer reports. The vulnerability (CVE-2026-73570) is a remote code execution flaw that can allow an attacker to "send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user." Zimbra maker Synacor issued a patch on July 20th, and CISA ordered Federal agencies to apply the patch by yesterday, August 24th. Organizations that haven't yet mitigated the flaw should do so immediately and audit for prior compromises.
The Shadowserver Foundation said that, as of yesterday, at least 8,200 unpatched Zimbra instances were exposed to the internet, although not all of these were in an exploitable configuration.
US Treasury Department levies sanctions on alleged Iranian hackers.
The US Treasury Department has levied a new set of sanctions on six Iranians accused of hacking for Iran’s Ministry of Intelligence and Security (MOIS). Four of these men were indicted by the US Justice Department last week for breaching email accounts at the Department of Labor, the Federal Energy Regulatory Commission, and United Nations entities. The Treasury Department says the individuals "have successfully compromised and exfiltrated data from multiple U.S. companies in various critical infrastructure sectors, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions." The hackers have also allegedly targeted Iranian companies for financial gain.