The 5-Minute Cyber Brief
Good morning. Here are the cybersecurity developments most likely to matter to your day.
Lead Story
Hackers breached over 270 Zimbra servers in ongoing attacks

CERT Polska says attackers are exploiting CVE-2026-73570, an unauthenticated command-injection flaw in Zimbra's SNMP notification handling that was patched in version 10.1.20 and can lead to remote code execution on exposed mail servers.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Why it matters: This matters because internet-exposed mail servers are still high-value targets, and more than 12,100 visible Zimbra systems means the real problem is not patch availability. It is whether teams can prove which servers are exposed, whether SNMP notifications are enabled, and whether compromise indicators are already sitting in logs.
Read more on CyberExperts: Read more on CyberExperts
Original source: BleepingComputer
Also Worth Your Attention
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Researchers say attackers used 24 npm packages not to infect developers directly, but to host fake Cloudflare CAPTCHA pages on trusted unpkg mirrors and redirect visitors into a ClickFix-style phishing chain.
Why it matters: This matters because the attacker is borrowing trust from legitimate package infrastructure instead of relying only on disposable phishing domains. If a mirror-hosted page on a recognized domain can serve the lure, casual URL checks and domain reputation become a much weaker safety net.
Read more on CyberExperts: Read more on CyberExperts
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

SOCRadar says the AnonyMousKIT phishing service has been helping criminals unlock stolen iPhones by combining realistic Apple-themed lures, fake Find My pages, and AI voice agents that pressure victims into dictating passcodes and account details.
Why it matters: This matters because stolen-device fraud is colliding with identity abuse. Once attackers collect the passcode, Apple ID, and 2FA details, the problem can expand from hardware resale into iCloud backups, Keychain secrets, work email, and other corporate data living on the same Apple account.
Read more on CyberExperts: Read more on CyberExperts
The safety penalty: Reclaiming operational sovereignty in the age of AI

Cisco Talos argues that cloud AI guardrails are becoming an incident-response liability for defenders, citing a July 2026 Hugging Face breach investigation where a primary cloud model refused forensic help and the team had to pivot to an unconstrained fallback model.
Why it matters: This matters because if your SOC depends on AI for malware analysis, deobfuscation, or incident triage, a model refusal during a live case is an operational failure, not a minor inconvenience. Attackers can move to less restricted models immediately, while defenders often discover their fallback gap mid-incident.
Read more on CyberExperts: Read more on CyberExperts
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

SOCRadar says E4del and PINHOLE are using FTP banners as dead drop resolvers, turning the protocol's welcome message into a way to deliver next-stage commands and command-and-control details for two previously unreported RAT campaigns.
Why it matters: This matters because defenders usually expect dead-drop tricks to hide in web traffic, not in an FTP welcome banner. That shifts the hunt from classic phishing detection alone to anomalous outbound FTP, WebDAV, and staged PowerShell or rundll32 activity that many teams may not be correlating tightly today.
Read more on CyberExperts: Read more on CyberExperts
Go Deeper
Editorial Promise
CyberExperts should help you get the signal fast, understand what actually matters, and know where to go deeper before the day gets noisy.