Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
2026-07-24T02:51:40Z•c973576a87aabd6d81710016aad2627c081015ee98ca1becae8028bf8d24e5a7
agentic-aiaiandroid-spywarecookie-trackinghalf-clickidentity-theftlaundry-bearllm-jailbreakspasskeysphishingransomwaresonicwallsupply-chainwordpresswp2shellzero-dayzimbra
What happened
A Wave of high-impact threats and systemic risks across web, email, and AI ecosystems. State-aligned group "Laundry Bear" is exploiting a Zimbra zero-day via “half-click” (open/preview) phishing to target US and Ukrainian organizations. Attackers are rapidly chaining known WordPress flaws (WP2Shell) — CVE-2026-60137 and CVE-2026-63030 — to mass-exploit sites, while Inc ransomware actors are chaining SonicWall SMA zero-days for root-level compromise. Concurrent themes include serious identity and passkey-implementation weaknesses, growing abuse of AI/LLM toolchains (jailbreaks, agentic AI risks
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- c973576a87aabd6d81710016aad2627c081015ee98ca1becae8028bf8d24e5a7
- Enrichment time
- 2026-07-24T02:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.