Security NEXTJuly 27, 2026🇯🇵Translated from Japanese

Russian State-Supported Group LAUNDRY BEAR Exploits Zero-Day CVE-2025-66376 in Zimbra Collaboration Suite

Synacor’s Zimbra Collaboration Suite (ZCS) was compromised through a previously unknown vulnerability that Russian state-supported hackers exploited in zero-day attacks.

The flaw, now tracked as CVE-2025-66376, resides in the stylesheet processing component of the webmail interface and constitutes a stored cross-site scripting issue.

Attackers sent crafted HTML-formatted messages; simply viewing the email in the browser triggered JavaScript execution, enabling theft of historical mailbox contents without any additional user clicks.

On 23 July 2026, authorities from the United States, Europe, Australia and other regions published a coordinated advisory signed by twenty-seven organizations, including the NSA, FBI and CISA.

Researchers attribute the operation to the group tracked as LAUNDRY BEAR, also known as Void Blizzard, CL-STA-1114 and TA488 (formerly UNK_PitStop).

MITRE assigned the vulnerability a CVSS v3.1 base score of 7.2, classifying it as High severity.

The campaign targeted Western government agencies and enterprises with the objective of collecting sensitive information.

Related articles

AntiMalwareState-Sponsored & APT

HoneyMyte APT Deploys Kernel-Level CoolClient Backdoor Disguised as Microsoft Defender

The Chinese-speaking APT group HoneyMyte has deployed an updated version of its CoolClient backdoor in espionage operations targeting government and private organizations in Russia, Myanmar, Mongolia, Pakistan, and India. The new variant operates at the Windows kernel level using a signed driver, allowing it to hide processes, files, registry entries, and network activity while evading detection. Attackers first abuse PlugX to add exclusions for Microsoft Defender, then drop a fake Windows Defender directory containing the renamed Sangfor binary defender.exe and the malicious libngs.dll. A scheduled task ensures persistence by launching the fake defender.exe with high privileges on system startup. Kaspersky GReAT researchers note that the kernel-mode capabilities significantly increase the backdoor’s stealth and survivability compared to its previous user-mode implementation. The campaign demonstrates sophisticated living-off-the-land techniques combined with legitimate software abuse.

BoletimSecState-Sponsored & APT

Lazarus Group Exploits Windows Kernel Zero-Day CVE-2026-68820 to Deploy FudModule Rootkit

The North Korean Lazarus APT group has been actively exploiting a zero-day vulnerability in the Windows kernel to escalate privileges to SYSTEM level and install the FudModule rootkit. The flaw, tracked as CVE-2026-68820, resides in the afd.sys driver responsible for network functions and socket management. Microsoft released a patch for the issue on August 11. The attacks form part of the ongoing Operation Dream Job campaign, which uses fake job offers to target professionals in defense, aerospace, and aviation sectors. Victims in Brazil, Europe, and India are tricked into opening malicious PDF viewers or prepared files that deliver the MISTPEN downloader. Once initial access is obtained, the zero-day exploit elevates privileges, allowing FudModule to tamper with Windows telemetry and weaken EDR solutions as well as Smart App Control.

BoletimSecState-Sponsored & APT

Iranian Hackers Disable Safety Alarms in US Industrial Control Systems

Iranian threat actors have been compromising internet-exposed industrial controllers across the United States since at least March 2026, modifying alarm and safety shutdown logic in critical infrastructure. The campaign has targeted government organizations and operators in the water, wastewater, and energy sectors, resulting in operational disruptions and financial losses. Attackers focus on devices with insecure remote access, weak credentials, or default configurations rather than exploiting zero-day vulnerabilities. Targeted hardware includes Rockwell CompactLogix and Micro850 controllers, Schneider BMX P34 and Modicon M340 PLCs, and Siemens S7-1200 models. Operators use rented foreign infrastructure and legitimate programming software to download, alter, and re-upload control logic projects. In at least one case, malicious code maintained normal operations while introducing instructions that bypassed safe operational limits and altered data displayed on HMI and SCADA interfaces. The tactics closely resemble prior activity attributed to the CyberAv3ngers group linked to Iran’s Islamic Revolutionary Guard Corps, though direct attribution remains unconfirmed.

安全客State-Sponsored & APT

Russian Intelligence Hijacks Exposed Security Cameras in Europe and Ukraine for Military Surveillance

Dutch intelligence agencies AIVD and MIVD have revealed that Russian military intelligence is systematically compromising internet-connected security cameras across Europe and Ukraine. The attackers scan for exposed devices using brand fingerprints, then log in with default passwords and outdated firmware without needing zero-day exploits. In Ukraine, live camera feeds are used not only for reconnaissance of military transport routes and weapon deliveries but also to directly support targeting of Ukrainian forces and equipment. Censys identified over 87,000 vulnerable cameras in the EU, NATO countries, and Ukraine, with more than 4,000 located in Ukraine alone. While the actual number of confirmed compromises is smaller, the cameras are strategically positioned along key military logistics routes. The agencies issued basic but critical recommendations including disabling public exposure, changing default credentials, and applying patches for known vulnerabilities such as CVE-2016-7407 and CVE-2021-39275.