Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers

In other news: US accuses Moonshot AI of distillation attacks; Iran is targeting more PLC vendors; Google adds selfie video login.

Share
Risky Bulletin: Western cyber agencies warn of Russian hacks of Zimbra servers

This newsletter is brought to you by Thinkst, the makers of the much-loved Thinkst Canary. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

Cybersecurity and intelligence agencies from multiple Western countries have issued joint security advisories on Thursday warning of a major Russian hacking campaign that's targeting Zimbra email servers.

The attacks have been going on since last year. The zero-day, tracked as CVE-2025-66376, was patched in November but attacks have been traced back to at least July.

The zero-day itself is a stored cross-site scripting (XSS) bug that allows the attackers to load malicious code inside a Zimbra webmail client via the CSS @import feature. The malicious code would load a web tool called Ulej (Russian for Beehive) that could be used to harvest credentials, session tokens, backup 2FA codes, browser-saved passwords, and the contents of the victim’s mailbox going back 90 days.

via Palo Alto Networks

Authorities linked the attacks to a group tracked as Laundry Bear, also known as Void Blizzard and TA488. They also warned that other groups may also be targeting the vulnerability.

Agencies say the campaigns lacked any financial extortion, focused on maintaining persistence and access to inboxes, and included "extensive Ukrainian targeting," either targeting Ukrainian entities, or organizations in the US and NATO space related to Russia's war.

While the use of a Zimbra zero-day is novel for Russian APTs, the targeting of non-Google and non-Microsoft email servers is not. Ever since its invasion of Ukraine in 2022, Russian hackers have been targeting lesser-known email technologies, such as Roundcube, Horde, MDaemon, SOGo, Zimbra, and others.

These types of email servers are often used in environments because of data compliance obligations or due to reduced hosting costs. Organizations that deal with sensitive information are actually very likely to use an on-premise email server like these, rather than a M365 or Google Workspaces setup that could expose or store sensitive data in US clouds and cause a compliance and risk management nightmare.

ESET has been tracking these Russian APT operations against lesser-known email servers as Operation RoundPress. Proofpoint, which has also been looking at the same attacks, says it spotted Russian espionage groups employing a wide assortment of both zero-days and n-days as part of their attacks.

For example, the EU itself had one of its on-premises Roundcube servers hacked by a Russian group known as Winter Wyvern back in 2023 using one of these zero-days.

Most of these bugs are stored XSS issues in the email server's webmail component, the GUI part that users access in their browser to read their emails.

Proofpoint describes most of these vulnerabilities as "half-click exploits, a term the company uses to describe that users only need to load a malicious email in their webmail interface to get hacked, even if they don't click on anything else, such as links inside the email itself.

📙
Public advisories: CISA // NSA // FBI // MIVD // AIVD // UK NCSC.

Risky Business Podcasts

The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and special guest co-host Chris Krebs at the helm!


Breaches, hacks, and security incidents

Thailand's MOF hacked with an AI agent: Hackers used an autonomous AI agent to hack the Thailand Ministry of Finance. The attackers used a version of the Hermes AI agent that was configured in "YOLO mode." The hack was discovered after a security researcher found an internet-exposed directory on the attacker's backend. The directory contained malware payloads and logs from the intrusion. [Hunt Intelligence]

Stadler Rail ransomware attack: The Everest ransomware group is holding Swiss train maker Stadler for ransom. Stadler says the group is asking for a ransom of 10 million Swiss francs, or roughly $12.3 million. The hackers allegedly breached a supplier and pivoted to a shared platform. The company says it won't pay. [Stadler Rail]

Origin Energy breach: Australian energy provider Origin Energy is investigating a security breach that may have exposed the data of its customers. [ABC // ASX filing, PDF]

UpBound breach: Hackers have breached fintech company UpBound and stolen customer information. The company says the stolen data was used to fraudulently rent furniture and electronics on the Acima marketplace. UpBound estimated the size of the fraudulent loan agreements at around $13 million. [SEC filing // MarketWatch]

Chick-fil-A breach: American restaurant chain Chick-fil-A is notifying users of a security breach that exposed some of their sensitive data, including the last four digits of their cards. [BleepingComputer]

Data leak exposes Shell's tax havens: Reporters from Follow The Money claim that data leaked from Shell's 2022 Accellion-related hack has exposed how the company is moving profits to tax havens to dodge taxes around the globe. [FTM]

Wanchain hacked for $10m: Hackers have stolen almost $10 million worth of crypto assets from the Wanchain cross-chain bridge. The hackers exploited a smart contract that handled transactions between the Cardano and the Binance blockchains. The funds were stolen across eight minutes before the platform could react. [Wanchain // The Crypto Times]

AFX Trade hacked for $24m: Hackers have stolen $24 million worth of cryptocurrency from the AFX Trade cross-chain bridge. The attackers allegedly obtained some of the bridge's private keys to sign the transactions that stole the funds. AFX trading activity had been climbing sharply prior to the hack, which might now deter customers from using it. [CoinDesk // AFX Trade]

Verus hacked for the second time this year: A hacker has stolen $7.5 million worth of Ether from the Verus Ethereum bridge. This is the company's second hack this year after it also lost $11.5 million in May. According to blockchain security firm Blockaid, the attacker exploited the same smart contract function from the first hack. [Cryptopolitan // Blockaid]

General tech and privacy

Google adds selfie login: Google will let users sign into their accounts using a selfie video of their face. The new login method was added this week for all Google account holders. The new selfie video option will also be used to help users recover their accounts, prove their human, and manage an AI avatar of themselves. [Google]

LG to suspend proxy apps from TVs: LG Electronics will suspend all apps on its smart TVs that turn the devices into residential proxy nodes. A study published last month found that 42% of all LG smart TVs contained apps with proxy-like behavior. LG Senior Vice President John Taylor says the company has contacted developers to remove the features from the apps or face a suspension. [KrebsOnSecurity]

Anthropic settlement: A US judge has approved a $1.5 billion settlement between Anthropic and some authors and publishers for scraping their books and using the text to train AI tools. It ​is the largest known copyright lawsuit and settlement in history. [Reuters]

EU fines Google: The EU has fined Google €890 million under the EU Digital Markets Act (DMA) for self-preferencing its own services in Google Search results. [EU]

PyPI adds upload restriction: The Python Package Index will automatically reject file uploads to package releases that are older than 14 days. PyPI admins introduced the measure to prevent threat actors from adding malware to known-safe releases. PyPI says it did not encounter such an attack yet, but there was nothing stopping attackers from poisoning older releases. [PyPI]

Firefox 153: Mozilla has released Firefox 153. New features and security fixes are included. The biggest feature in this release is the initial support for Containers, a feature to separate a user's data so multiple profiles can run in the same browser session. Firefox also has a built-in QR code generator to share QR images for specific URLs.

Government, politics, and policy

US has a duplicate cyber rules problem: About 70% of all US cybersecurity reporting rules used across 37 agencies contain overlapping reporting requirements. The Government Accountability Office examined the reporting conflicts at the request of US lawmakers. The Trump administration has made it a priority last year to deconflict and simplify reporting requirements and cyber rules. [US GAO // CyberScoop]

US to impose visa restrictions on scammers: The US State Department will impose visa restrictions on known individuals linked to cyber scam and sextortion operations. The visa restrictions also apply to immediate family members. In a March executive order, the White House ordered US federal agencies to prioritize the fight against scams and cybercrime. [US State Department]

CISA 2015 extension passes House: A 10-year extension to the 2015 Cybersecurity and Information Sharing Act has passed the US House as part of the larger 2027 National Defense Authorization Act (NDAA). [The Record]

US AI labs are new targets: Former US intelligence officials have told Congress that US AI labs have emerged as a prime target for foreign hackers and that the intelligence community has done little to help the labs defend their proprietary AI. [NextGov]

US accuses Moonshot of distillation attack: A top White House official has accused Chinese AI startup Moonshot of distillation attacks against Anthropic. Michael Kratsios says Moonshot distilled Anthropic's recently-released Fable model to develop its own Kimi K3 product. Kratsios leads the White House Office of Science and Technology Policy. US Treasury Secretary Scott Bessent hinted at possible sanctions against the AI company on Wednesday. [The New Stack // Singulism // Michael Kratsios tweet]

A company that uses distillation to make its AI models should not be called "Moonshot," but rather "Moonshine." Ba-dum-tss

— Asa Dotzler (@asadotzler.com) July 22, 2026 at 10:48 PM

In this Risky Business sponsor interview, Casey Ellis chats with Haroon Meer from Thinkst about building companies customers don’t hate. Haroon explains why Thinkst still offers Canary tokens for free and why it has avoided annual price hikes on its paid products. They talk about Eric Ries’s “Incorruptible”, Rob Lee’s 100-year-company approach at Dragos, and why keeping customers happy is a better business strategy than chasing easy sugar highs. 

Arrests, cybercrime, and threat intel

Snapchat hacker sentenced to jail: An Illinois man was sentenced to six years in prison for hacking the Snapchat accounts of almost 600 women. Kyle Svara stole nude and semi-nude images, which he later sold or traded online. He also sold his hacking services online. One of the people who hired Svara was Steve Waithe, a former Track and Field Coach at Northeastern University, who paid him to hack his students' accounts. [Reuters]

Major fraudster detained in India: Indian police have arrested a suspect this week on charges of laundering money from cyber fraud operations. Ghanshyam Kalal allegedly worked for a scam group operating out of Dubai. The suspect allegedly convinced Indian citizens to open bank accounts to receive government benefits, but later repurposed the accounts in a money laundering operation. [The 420]

China extradites Silver Fox member: Chinese authorities have extradited from Vietnam a suspected member of the Silver Fox cybercrime group. The suspect allegedly built phishing sites to distribute the Silver Fox trojan. Chinese authorities are cracking down on the group, which is believed to be the country's largest and most active cybercrime operation. They previously arrested 67 suspects in June. [China Daily // Risky Business]

XEntry Team: A ransomware crew going by the XEntry Team is hacking into organizations through misconfigured MSSQL servers, using BitLocker to lock files, and sending ransom notes to local printers to request payment. The attacks have been spotted in Mexico this year. [Kaspersky]

TAG-195 (Golden Chickens): The TAG-195 cybercrime group, which operates the Golden Chickens MaaS, has been spotted wielding four new malware strains—TinyEgg, ChonkyChicken, a modularized version of ChonkyChicken, and ChromeEggscalator. [Recorded Future]

New Clop targeting: The Clop ransomware group has been seen targeting internet-exposed PTC Windchill and FlexPLM servers. [Ransom-ISAC]

Malicious GitHub Actions campaign: Socket researchers have found an operation using a unique way of spreading malicious GitHub Actions, by hiding it in a project's "vendor" directory where it's only executed under certain scenarios. [Socket Security]

VS Code extensions steals your data: A malicious VS Code extension that uses the stolen branding of a legitimate one (Markdown All in One) has been stealing sensitive data from infected machines, most likely recon data for future malware drops. [Manifold Security]

Claude malvertising campaign: A malvertising campaign infected users with the SectopRAT after hosting malicious Claude-related artifacts on some parts of the official Claude domain. [Huntress]

AfterCall ads: Security researchers have found a cluster of malicious apps that work by showing an ad every time an infected user hangs up on a call. [DoubleVerify]

Malware technical reports

SANDWORM_MODE: CrowdStrike has published an analysis of SANDWORM_MODE, one of the npm worms from earlier this year. According to the company, the worm used many AI-based tools but appears to have only been a proof-of-concept. [CrowdStrike]

New TrickBot: Fortinet has spotted a rare new version of TrickBot, a botnet that was supposed to be dead but it's still limping around somehow. [Fortinet]

SocGolish: Security researcher Matt Kirkland looks at a SocGolish campaign that infected more than 1,500 WordPress sites since April. [Matt Kirkland]

msaRAT: The Chaos ransomware operation seems to have developed its own Rust-based RAT to use in intrusions. Cisco tracks this new tool as the msaRAT. The main innovation here is the use of Chrome browser protocols to hide and control its C2. [Cisco Talos]

"This RAT never touches the network directly — it controls its C2 communication channel exclusively through Chrome DevTools Protocol (CDP), a browser debugging API. The binary contains a Cloudflare Workers endpoint, but it never makes HTTP connections to that domain itself; it offloads that work entirely to the browser. saRAT manipulates the browser via CDP, performs signaling (SDP Offer/Answer exchange) with Cloudflare Workers, and establishes a WebRTC DataChannel between the browser and the C2 server using Twilio TURN (Traversal Using Relays around NAT) as a relay."

Dolphin X Stealer: A new infostealer named Dolphin X is being advertised on underground hacking forums. [Varonis]

In this Soap Box edition of the podcast, Patrick Gray chats with Thinkst Canary founder Haroon Meer about his "decade of deception." 

APTs, cyber-espionage, and info-ops

OpSec leak exposes JadeProx operations: A misconfigured web directory has exposed the operations of a Chinese espionage group named JadeProx. The server exposed web shells and phishing operations that targeted the Malaysian Ministry of Foreign Affairs, Vietnamese public hospital, and multiple Hong Kong educational institutions. Group-IB researchers also found a new malware loader named TriBack that appears to have been used in some of the attacks. [Group-IB]

Mustang Panda's ToneShell: Malware researcher Kien Tran Trung (aka kienmanowar) has published an analysis of ToneShell, a backdoor typically used in Mustang Panda APT operations only. [Kien Tran Trung]

UAC-0099: A Russian cyber-espionage group tracked as UAC-0099 is distributing malware disguised as Notepad++ plugins. [CERT-UA]

Kimsuky ops: Researchers take a look at three Kimsuky campaigns impersonating diplomats and targeting foreign affairs workers and South Korean groupware vendors. [AhnLab // AhnLab // ENKI]

DPRK job interviews adopt ClickFix: North Korean hacking groups have adopted the ClickFix technique during fake job interview operations. Victims who applied for a fake job are now being asked to access websites that have a fake CAPTCHA challenge. The CAPTCHA instructs applicants to run malicious terminal commands on their PCs that infect them with malware. The technique has been widely used last year by e-crime groups but is now being slowly adopted by state-sponsored groups as well. [SOCRadar]

Operation RoundPress, part 2: A GRU hacking group tracked as TA458 has continued to hack webmail clients despite having its operations exposed earlier this year. Recent operations included the use of three zero-days and two n-days. [Proofpoint]

"Proofpoint assesses that TA458 is likely a Russian military intelligence operation directed by the Russian GRU. At the time of writing, there is no indication of targeting overlap in Proofpoint telemetry between TA458 and TA422 (Sofacy, APT28, Fancy Bear, Forest Blizzard), which has been attributed to GRU Unit 26165."

More espionage with fake civil defense apps: Dream security researchers have found a malicious Android application that impersonates the Bahraini Civil Defense app "BH Alert" missile strike siren and civil defense app. [Dream]

MuddyWater's PatchAgent: The Ransom-ISAC group has reverse-engineered PatchAgent, one of the malware loaders used by Iranian APT group MuddyWater. [Ransom-ISAC]

Iran PLC activity update: Iranian hackers have expanded their operations targeting internet-exposed programmable logic controllers (PLCs). CISA is reporting new attacks targeting PLCs from Siemens and Schneider Electric. Iranian hackers started targeting PLCs as a retaliatory measure after US and Israeli troops attacked the country. Initial attacks targeted Rockwell and Allen-Bradley PLCs. [CISA]

The Iran cyber war landscape: SentinelOne takes another top-down view of Iran's cyber landscape and how the regime responded since it was attacked by the US and Israel earlier in the year. [SentinelOne]

"We assess with moderate confidence that Iran-linked operators will attempt selective disruption where three conditions coincide: usable access already exists, the victim has political or symbolic value, and the expected effect can be achieved without an unacceptable risk of escalation or exposure. Administrative and management systems are particularly relevant because they translate ordinary enterprise access into organization-wide effects."

Vulnerabilities, security research, and bug bounty

Security updates: Firefox, Oracle, Tor Browser.

GitHub announces VIP bug bounty program: Github is launching a private, invite-only VIP bug bounty program for vetted security researchers. The company is launching the program after it's been flooded with low-quality AI-generated bug reports. The new program will provide higher rewards to bug hunters. The rewards in the normal bug bounty program have also been lowered to as low as $250. [GitHub]

Github pays $100k for RCE bug: GitHub has awarded Wiz security researcher Sagi Tzadik a $100,000 bounty for a major security flaw. The vulnerability would have allowed attackers to take over private GitHub Enterprise servers but also access other users' code on the main GitHub.com service. Exploitation required only a single git push command. GitHub fixed the issue six hours after the report. [Wiz]

Oracle has its own bugpocalypse: The quarterly Oracle security updates are out, with patches for 1,449 vulnerabilities. Yes, you read that right. Tenable has a breakdown of the fixes. [Oracle // Tenable]

Check Point patches zero-day: Check Point has released security updates for a zero-day in its SmartConsole GUI management application. Tracked as CVE-2026-16232, the zero-day allows attackers to bypass authentication and gain full admin rights on the app. The SmartConsole app is used by Check Point customers to manage Check Point products deployed across a customer's network. [Check Point]

Windmill bug enters active exploitation: Hackers are exploiting a vulnerability to gain access to Windmill server infrastructure management panels. The attackers are exploiting a path traversal bug to recover a SUPERADMIN_SECRET token from Windmill installations. Authentication is not required to retrieve the token. The vulnerability was patched in January and first attacks were seen last week. [VulnCheck // CVE-2026-29059]

HermeticReader vulnerability: Security researchers have found a way to weaponize the Adobe Acrobat Chrome extension into a one-click WhatsApp exfiltration tool. The extension was downloaded more than 239 million times and will need an update. [Guardio]

RefluXFS vulnerability: A new vulnerability in the Linux kernel can allow local attackers to overwrite local files and gain root access. Named RefluXFS, the vulnerability is a race condition in the Linux XFS filesystem. It impacts all Linux kernel versions released over the past nine years. According to Qualys, exploitation is highly reliable, persists across a system reboot, and leaves no traces in the kernel log. [Qualys // CVE-2026-64600]

Windows Event Logging RCE: Login Sécurité's Romain Bentz has published a write-up on a bug in the Windows Event Logging service that can be abused for remote code execution. Microsoft patched Bentz's bug this month. [CVE-2026-50502]

Wansview cameras ship with 24yo vuln: Some Wansview security camera models ship with firmware that contains a 2002 vulnerability, an infamous ../ path traversal issue that could be exploited via the camera's built-in web server. [Finite State]

Infosec industry

Threat/trend reports: Check Point, InfraTrust, JPCERT/CC, Microsoft, NCC Group, Positive Technologies, Proofpoint, Red Canary, Vectra AI, and WitnessAI have recently published reports and summaries covering various threats and infosec industry trends.

New Meta CISO: Social media giant Meta has appointed Assaf Keren as its new chief information security officer (CISO). Keren replaces Guy Rosen, who retired last month after 13 years at the company. Keren previously served as CISO at PayPal and Qualtrics, and also co-founded security firm SenseCy. [TheNextWeb]

PETS 2025 videos: Talks from the Privacy Enhancing Technologies Symposium, which took place earlier this month, are available on YouTube

Risky Business podcasts

In this edition of Seriously Risky Business, Tom Uren and James Wilson talk about the future of open-weight models. For different reasons, both the Chinese and American governments have reasons to crack down on them.