Threat Management , Threat Intelligence Russian hackers exploited Zimbra zero-day in espionage campaigns July 27, 2026 Share By SC Staff Russian state-sponsored cybercriminals exploited a zero-day vulnerability in the Zimbra email and collaboration platform to conduct espionage against Western targets, primarily military and government agencies, according to a recent report by Tech Radar. Proofpoint reports that the threat group TA488, also known as Laundry Bear or Void Blizzard, leveraged a cross-site scripting (XSS) vulnerability, tracked as CVE-2025-66376, in Zimbra's web-based email service. This "half-click exploit" allowed attackers to compromise systems simply when victims viewed malicious emails, without requiring any further interaction. The campaign targeted NATO, Ukrainian government organizations, and entities within the defense industrial base. After gaining access, TA488 exfiltrated emails, passwords, two-factor authentication tokens, and other sensitive information. The group consistently targeted these entities for at least a year before their activity ceased in February 2026, following the public disclosure of their methods by security researchers, which led to their disappearance. Source: Tech Radar SC Staff Related Security Operations The enduring mystery of hacker Phineas Fisher SC Staff July 27, 2026 As outlined in TechCrunch, the enigmatic hacker known as Phineas Fisher remains one of the most elusive and impactful figures in cybersecurity, a decade after their most notorious exploits. Malware Golden Chickens malware-as-a-service resurfaces with four new families SC Staff July 24, 2026 The Hacker News disclosed that the threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. Threat Management UK issues alert over Russian zero-click email attacks SC Staff July 24, 2026 The UK's National Cyber Security Centre (NCSC) issued an alert regarding a new 'zero-click' threat campaign orchestrated by Russian state-backed hackers targeting organizations across critical sectors, according to a recent report by IT Pro. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Cybercast RSAC Preview: Exposure management takes center stage On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Backdoor DNS Spoofing Deauthentication Attack Defacement Distributed Scans Domain Hijacking DumpSec Google Hacking Password Cracking Reconnaissance You can skip this ad in 5 seconds