Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

23/07/2026 0 Comments 0 tags

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client. The payload goes after the last 90 days of email, the organization’s

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

23/07/2026 0 Comments 0 tags

Most of this week’s trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

23/07/2026 0 Comments 0 tags

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

23/07/2026 0 Comments 0 tags

The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

23/07/2026 0 Comments 0 tags

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic’s Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which

Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

23/07/2026 0 Comments 0 tags

Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

23/07/2026 0 Comments 0 tags

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity

How Synthetic Identity Fraud is Coming for Machine Identities

23/07/2026 0 Comments 0 tags

Most people understand identity theft as an attacker stealing a real person’s sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

23/07/2026 0 Comments 0 tags

RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

23/07/2026 0 Comments 0 tags

Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the