Daily Security Intel

Archives
Log in
Subscribe
July 24, 2026

[SecurityIntel] 24 Jul | Russian State Hackers Exploit Zimbra Zero-Click Zero-Day

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Friday, July 24, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Russian State Hackers Exploit Zimbra Zero-Click Zero-Day

CRITICAL

5

C2 IPs

79

OTX IOCs

34

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by active zero-day exploitation, notably a newly disclosed Check Point vulnerability (CVE-2026-16232) and a Russian state-sponsored campaign by Laundry Bear exploiting a zero-click Zimbra flaw to steal emails. Additionally, emerging threats target AI ecosystems, including a sandbox escape in Anthropic's Claude Cowork and the "AgentForger" flaw in OpenAI's ChatGPT. Cybercriminals are also leveraging AI for target profiling (Dolphin X) and abusing legitimate platforms like GitHub Actions and Notepad++ plugins for malware delivery.

■ CRITICAL STORIES

CRITICAL#1

New Check Point Zero-Day Vulnerability CVE-2026-16232 Exploited in the Wild

Attackers are actively exploiting a newly disclosed zero-day vulnerability in Check Point Security Gateways, requiring immediate remediation.

CRITICAL#2

Russian Espionage Group Laundry Bear Exploits Zimbra Zero-Day

A Kremlin-backed group used zero-click phishing and JavaScript injection to compromise Zimbra webmail servers globally, stealing emails and 2FA codes.

HIGH#3

Claude Cowork Sandbox Escape Allows Host File Access

Researchers discovered a critical sandbox escape vulnerability in Anthropic's Claude Cowork, allowing an AI agent to escape its Linux VM and access files on host macOS systems.

HIGH#4

OpenAI Fixes "AgentForger" Flaw in ChatGPT

A vulnerability in ChatGPT allowed attackers to create and remotely control invisible, autonomous AI agents inside victim organizations.

■ CVEs IDENTIFIED

CVE-2026-16232

Check Point Security Gateway — Zero-day vulnerability exploited in the wild against specific customer configurations.

Critical

[CVE-TBD]

Zimbra Collaboration Suite — Zero-click JavaScript injection vulnerability exploited by Laundry Bear to steal emails and 2FA codes.

Critical

[CVE-TBD]

Anthropic Claude Cowork — Sandbox escape vulnerability allowing Linux VM breakout to access host Mac files.

High

[CVE-TBD]

OpenAI ChatGPT — AgentForger vulnerability allowing unauthorized creation and control of invisible autonomous AI agents.

High

■ THREAT ACTORS

Laundry Bear (Void Blizzard)

State-sponsored (Russia)

Exploited Zimbra zero-day via zero-click phishing to steal 90 days of emails and 2FA codes.

JadeProx

State-sponsored (China)

Targeted government, healthcare, and education in Asia and Latin America using TriBack Loader.

Chaos Ransomware Group

Cybercrime

Deployed msaRAT to route C2 traffic through headless Chrome and Edge browsers.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploitation of Check Point CVE-2026-16232 and Zimbra zero-day.
T1566.002
Spearphishing Link | Zero-click phishing used by Laundry Bear to inject malicious JavaScript.
T1574.012
DLL Side-Loading | Abuse of Notepad++ plugins to load the LunchPoke malware.
T1071.001
Web Protocols | Routing C2 traffic through headless Chrome/Edge browsers via msaRAT.
T1588.002
Tool | Use of Dolphin X malware utilizing AI-powered profiling to rank high-value targets.
T1110.004
Credential Stuffing | Automated attacks against Chick-fil-A One accounts.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Check Point — CVE-2026-16232 zero-day exploited in the wild — SecurityWeek

[P1 PATCH NOW]≤24h

Zimbra — Zero-click zero-day exploited by Russian state actors — CISA / Unit 42

[P2 PATCH NOW]≤72h

Adobe — HermeticReader Acrobat extension vulnerability — Malwarebytes

[P2 PATCH NOW]≤72h

Anthropic — Claude Cowork sandbox escape — The Hacker News

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch Check Point Security Gateways immediately to remediate the actively exploited CVE-2026-16232 vulnerability.
2[P1] Apply the latest security patches to Zimbra Collaboration Suite to block the zero-click JavaScript injection exploits used by Laundry Bear.
3[P1] Update the Adobe Acrobat Chrome Extension to the latest version to mitigate the HermeticReader vulnerability.
4[P2] Update Anthropic Claude Cowork to ensure the sandbox escape vulnerability is resolved.
5[P2] Implement application whitelisting and monitor Notepad++ plugin directories (e.g., %APPDATA%\Notepad++\plugins) for unauthorized DLLs.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 25 Jul | Autonomous AI Agents Weaponized for Enterprise Attacks Older → [SecurityIntel] 23 Jul | SharePoint and Langflow Flaws Face Active Exploitation
Powered by Buttondown, the easiest way to start and grow your newsletter.