daily cyber × ai intelligence

index

tagged

[laundry-bear]

3 editions · 3 items

July 30, 2026

  • TA488 (Laundry Bear / Void Blizzard) is exploiting an Outlook Web Access XSS zero-day (CVE-2026-42897) for persistent mailbox access (earlier coverage). Proofpoint says the Russia-aligned actor began the campaign on July 22, targeting US and European government, telecom, financial, hospitality and aerospace orgs, and is doubling down on "half-click" exploits where merely opening the email triggers compromise. Proofpoint, The Record · Threat Activity

in OpenAI's Rogue Agent Widens: Four More Companies Caught in the Blast Radius

July 24, 2026

  • A US/UK-led coalition exposed a Russian state campaign exploiting Zimbra zero-click flaw CVE-2025-66376 against NATO, Ukraine, CIS and African targets. The actor — tracked as Laundry Bear / Void Blizzard / TA488 (CL-STA-1114) — plants malicious JavaScript that fires the instant a webmail message is previewed, no click required; its Ulej tool then exfiltrates the last 90 days of email, org directories, saved browser passwords, and 2FA recovery codes. CISA advisory, NCSC-UK, Unit 42, The Record. · Threat Activity

in The Week AI Agents Started Doing the Hacking