July 26, 2026
- Russia's Laundry Bear (Void Blizzard / TA488) campaign against Zimbra got a technical anatomy from Unit 42, tracking it as CL-STA-1114: the zero-click XSS payload (CVE-2025-66376) grabs the last 90 days of mail, the org's full email directory, browser-saved passwords, and 2FA recovery codes the moment a message loads, per The Hacker News and BleepingComputer (earlier coverage).
· Threat Activity
in Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts
July 25, 2026
- Russian Zimbra campaign broadens across webmail platforms. Proofpoint expands the picture on the state-linked actor (TA488 / Void Blizzard / Laundry Bear), tying the "half-click" Zimbra XSS (CVE-2025-66376) to a wider Operation RoundPress push that also weaponized zero-days in mDaemon (CVE-2025-3929) and SOGo (CVE-2026-8496) (earlier coverage). Proofpoint.
· Threat Activity
in A Default-Config RCE Cracks GitLab, and the PoC Is Already Public
July 24, 2026
- A US/UK-led coalition exposed a Russian state campaign exploiting Zimbra zero-click flaw CVE-2025-66376 against NATO, Ukraine, CIS and African targets. The actor — tracked as Laundry Bear / Void Blizzard / TA488 (CL-STA-1114) — plants malicious JavaScript that fires the instant a webmail message is previewed, no click required; its Ulej tool then exfiltrates the last 90 days of email, org directories, saved browser passwords, and 2FA recovery codes. CISA advisory, NCSC-UK, Unit 42, The Record.
· Threat Activity
in The Week AI Agents Started Doing the Hacking