Russian hackers exploit Zimbra zero-click flaw for email theft

2026-07-23T19:23:26Z4de13f7dbd05fe68bf7f0eefb664f44bc57285e6935a4ddba7f1e44c4d849e1e
Adobe Acrobat extensionCVE-2026-64600Check PointChromeEU DMA fine (Google)EdgeExchange OnlineFedRAMP 20XLaundry BearLunchPokeMicrosoft 365 outageNotepad++RefluXFSSmartConsoleVoid BlizzardWhatsApp WebXFSZimbrabrowser C2local privilege escalationmsaRATphishingplugin abusezero-clickzero-day

What happened

Multiple active threats and high-impact incidents reported: Russian state-sponsored group Laundry Bear (Void Blizzard) is exploiting a patched Zimbra zero-click vulnerability combined with phishing to steal email; Check Point SmartConsole contains an actively exploited zero-day; RefluXFS (CVE-2026-64600) is a local race-condition XFS flaw allowing root escalation; new msaRAT backdoor tunnels C2 through Chrome/Edge; attackers are abusing Notepad++ installers/plugins (LunchPoke) to deliver persistence and malware; an Adobe Acrobat Chrome extension flaw exposed WhatsApp Web chats; several large‑m

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
4de13f7dbd05fe68bf7f0eefb664f44bc57285e6935a4ddba7f1e44c4d849e1e
Enrichment time
2026-07-23T19:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Russian hackers exploit Zimbra zero-click flaw for email theft · Baitaphish