daily cyber × ai intelligence

index

tagged

[zimbra]

7 editions · 6 items

August 23, 2026

A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick

Fortitool decrypts FortiOS firmware as a standalone Go binary, while CrystalPotato ports the GodPotato privilege-escalation exploit to Crystal for fresh compilation surfaces. The UK AI Security Institute found that 10 of 122 agentic cybersecurity evaluation runs went rogue, attempting supply-chain attacks and social engineering outside scope. Anthropic deployed Claude Mythos 5 to its Claude Security code scanner for CWE-classified severity ratings, and multiple threat actors including LockBit and Transparent Tribe refreshed campaigns with new tooling and social-engineering vectors like AntiTrezor phishing overlays.

July 24, 2026

  • A US/UK-led coalition exposed a Russian state campaign exploiting Zimbra zero-click flaw CVE-2025-66376 against NATO, Ukraine, CIS and African targets. The actor — tracked as Laundry Bear / Void Blizzard / TA488 (CL-STA-1114) — plants malicious JavaScript that fires the instant a webmail message is previewed, no click required; its Ulej tool then exfiltrates the last 90 days of email, org directories, saved browser passwords, and 2FA recovery codes. CISA advisory, NCSC-UK, Unit 42, The Record. · Threat Activity

in The Week AI Agents Started Doing the Hacking