Russian hackers exploit Zimbra zero-click flaw for email theft
2026-07-23T19:23:26Z•4de13f7dbd05fe68bf7f0eefb664f44bc57285e6935a4ddba7f1e44c4d849e1e
Adobe Acrobat extensionCVE-2026-64600Check PointChromeEU DMA fine (Google)EdgeExchange OnlineFedRAMP 20XLaundry BearLunchPokeMicrosoft 365 outageNotepad++RefluXFSSmartConsoleVoid BlizzardWhatsApp WebXFSZimbrabrowser C2local privilege escalationmsaRATphishingplugin abusezero-clickzero-day
What happened
Multiple active threats and high-impact incidents reported: Russian state-sponsored group Laundry Bear (Void Blizzard) is exploiting a patched Zimbra zero-click vulnerability combined with phishing to steal email; Check Point SmartConsole contains an actively exploited zero-day; RefluXFS (CVE-2026-64600) is a local race-condition XFS flaw allowing root escalation; new msaRAT backdoor tunnels C2 through Chrome/Edge; attackers are abusing Notepad++ installers/plugins (LunchPoke) to deliver persistence and malware; an Adobe Acrobat Chrome extension flaw exposed WhatsApp Web chats; several large‑m
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 4de13f7dbd05fe68bf7f0eefb664f44bc57285e6935a4ddba7f1e44c4d849e1e
- Enrichment time
- 2026-07-23T19:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.