Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

Russian State-Backed Hackers Exploit Zimbra Zero-Day Vulnerability Against US and Ukraine Targets A sophisticated Russian state-sponsored threat group, known as “Laundry Bear,” has been using a previously unknown vulnerability in the Zimbra Collaboration Suite (ZCS) to breach networks of Western governments and enterprises. The attack, which involves a “half-click” phishing campaign, has compromised networks across … Read more

Check Point warns of SmartConsole zero-day exploited in attacks

Check Point Warns of SmartConsole Zero-Day Exploit, Urgent Patching Advised Israeli cybersecurity firm Check Point Software has issued a warning about an actively exploited zero-day vulnerability in its SmartConsole graphical user interface (GUI) admin panel. The flaw, tracked as CVE-2026-16232, allows unauthenticated attackers to obtain an application login token that can be used to authenticate … Read more

Microsoft working to fix Exchange Online mailbox quarantine issue

A critical issue has been plaguing Microsoft’s Exchange Online service, causing widespread disruptions for users worldwide. Since Sunday, July 19, thousands of Exchange Online mailboxes have been mistakenly quarantined due to an out-of-memory condition triggered by a recent infrastructure change. The result is that many users are struggling to send and receive emails, while others … Read more

Is Patching Dead? Vulnerability Management in the Post-Mythos Era

The Vulnerability Management Crisis: Is Patching Dead? A major shift is underway in the way governments and organizations approach cybersecurity. The White House’s Gold Eagle initiative, launched on July 14, 2026, marks a significant departure from the traditional model of humans finding and patching vulnerabilities one at a time. Instead, advanced AI is being harnessed … Read more

OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider

A Critical Flaw in OpenAI’s ChatGPT Workspace Agents Exposes Organizations to Insider Threats Cybersecurity researchers have uncovered a severe vulnerability in OpenAI’s ChatGPT Workspace Agents, which could allow attackers to create an invisible autonomous agent that can be remotely controlled and used for malicious activities. The flaw, dubbed “AgentForger,” is a tailored cross-site request forgery … Read more

Flaws in Passkey Implementation Show Old Attacks Still Work

As Microsoft gears up to make passkeys the default authentication method for its cloud-based identity and access management service, a closer look at their implementation has revealed some unsettling vulnerabilities. Researchers from SpecterOps have found three nearly exploitable zero-day flaws in Windows 11 and Microsoft Entra ID that could allow attackers to impersonate privileged users, … Read more

Agentic AI Challenges Progress in Confidential Computing

As Confidential Computing Hits Mainstream, Agentic AI Presents New Security Challenges The adoption of confidential computing has been gaining momentum in recent years, thanks to significant advancements in technology. However, a new threat model is emerging as artificial intelligence (AI) becomes increasingly prevalent in enterprises. Agentic AI, which refers to AI agents that can think … Read more

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

Russian State-Sponsored Hackers Exploit Zimbra Zero-Day in Sophisticated Phishing Campaign A highly sophisticated phishing campaign has been uncovered, targeting Western governments and enterprises through a vulnerability in the popular email management system, Zimbra Collaboration Suite (ZCS). The attack, attributed to a Russian state-sponsored threat group dubbed “Laundry Bear,” has compromised networks of US and Ukrainian … Read more

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

A New Era of Stealthy Malware: msaRAT Uses Browsers to Route C2 Traffic Cybersecurity researchers have uncovered a sophisticated new backdoor dubbed msaRAT that is being used by the Chaos ransomware gang to evade detection and maintain control over compromised systems. What’s particularly noteworthy about this malware is its ability to route command-and-control (C2) communication … Read more

New RefluXFS Linux flaw lets attackers gain root privileges

A new Linux vulnerability has been discovered that allows attackers to gain root privileges on systems with an XFS filesystem. Dubbed RefluXFS by the Qualys Threat Research Unit (TRU), this security flaw affects millions of Linux users worldwide and poses a significant threat to system integrity. The vulnerability, tracked as CVE-2026-64600, has been present in … Read more