International alert spotlights Russia-linked attacks on Zimbra webmail
2026-07-24T02:51:52Z•80b80e8d5ba3b36941302241434eef354952492d1a9b291b9ad27c8e3e859d0d
CISA 2015EverestLaundry BearOrigin EnergyRussia-linked APTStadler RailState Department visa restrictionsZimbradata breachinformation sharingnation-stateransom demandransomwaretransnational cyber-scamswebmail compromisezero-click phishing
What happened
A multi-item briefing: an international alert says Kremlin-linked Laundry Bear is using a zero-click phishing technique to compromise Zimbra webmail accounts worldwide, enabling account takeover without user interaction. Other notable items: the U.S. State Department announced visa restrictions targeting individuals tied to transnational cyber-scam operations; Australian energy supplier Origin Energy confirmed a customer data breach; Stadler Rail refused a $12.3M ransomware demand after technical data was stolen from a supplier; and Congress included a 10-year extension of CISA 2015 info‑shar‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- 80b80e8d5ba3b36941302241434eef354952492d1a9b291b9ad27c8e3e859d0d
- Enrichment time
- 2026-07-24T02:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.