International alert spotlights Russia-linked attacks on Zimbra webmail

2026-07-24T02:51:52Z80b80e8d5ba3b36941302241434eef354952492d1a9b291b9ad27c8e3e859d0d
CISA 2015EverestLaundry BearOrigin EnergyRussia-linked APTStadler RailState Department visa restrictionsZimbradata breachinformation sharingnation-stateransom demandransomwaretransnational cyber-scamswebmail compromisezero-click phishing

What happened

A multi-item briefing: an international alert says Kremlin-linked Laundry Bear is using a zero-click phishing technique to compromise Zimbra webmail accounts worldwide, enabling account takeover without user interaction. Other notable items: the U.S. State Department announced visa restrictions targeting individuals tied to transnational cyber-scam operations; Australian energy supplier Origin Energy confirmed a customer data breach; Stadler Rail refused a $12.3M ransomware demand after technical data was stolen from a supplier; and Congress included a 10-year extension of CISA 2015 info‑shar‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
80b80e8d5ba3b36941302241434eef354952492d1a9b291b9ad27c8e3e859d0d
Enrichment time
2026-07-24T02:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.