Marathon Petroleum’s CISO on OT security automation, supply chain risk

2026-07-27T08:51:39Z8564d0f240f2360405bfcdac3d5d4d1d3e86a15e1df4b31861cd3cd8154a154a
CVE-2025-66376AI agent securityDependabot cooldownLaundry BearMFA fatigueOT securityRussian state-sponsored threat actorServiceNowTPMVoid BlizzardWindows KMSZimbraauthenticationemail theftidentity attacksnpm malwarepre-auth RCEprompt injectionsession token theftsoftware supply chainsupply chain riskunpatched serversvulnerability exploitation

What happened

Help Net Security coverage highlights OT security and supply-chain risk, AI-agent sandboxing, identity attacks, authentication, software supply-chain malware, AI model security, major breaches, social-media identity verification, exploitation of Zimbra servers by Russian state-backed actors, and TPM-backed Windows KMS security. The most actionable threat intelligence concerns active exploitation of Zimbra vulnerability CVE-2025-66376 by Laundry Bear/Void Blizzard to steal email from unpatched government and commercial systems, alongside poisoned npm packages and in-the-wild ServiceNow RCE. The

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
8564d0f240f2360405bfcdac3d5d4d1d3e86a15e1df4b31861cd3cd8154a154a
Enrichment time
2026-07-27T08:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.