Marathon Petroleum’s CISO on OT security automation, supply chain risk
2026-07-27T08:51:39Z•8564d0f240f2360405bfcdac3d5d4d1d3e86a15e1df4b31861cd3cd8154a154a
CVE-2025-66376AI agent securityDependabot cooldownLaundry BearMFA fatigueOT securityRussian state-sponsored threat actorServiceNowTPMVoid BlizzardWindows KMSZimbraauthenticationemail theftidentity attacksnpm malwarepre-auth RCEprompt injectionsession token theftsoftware supply chainsupply chain riskunpatched serversvulnerability exploitation
What happened
Help Net Security coverage highlights OT security and supply-chain risk, AI-agent sandboxing, identity attacks, authentication, software supply-chain malware, AI model security, major breaches, social-media identity verification, exploitation of Zimbra servers by Russian state-backed actors, and TPM-backed Windows KMS security. The most actionable threat intelligence concerns active exploitation of Zimbra vulnerability CVE-2025-66376 by Laundry Bear/Void Blizzard to steal email from unpatched government and commercial systems, alongside poisoned npm packages and in-the-wild ServiceNow RCE. The
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 8564d0f240f2360405bfcdac3d5d4d1d3e86a15e1df4b31861cd3cd8154a154a
- Enrichment time
- 2026-07-27T08:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.