SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefFriday, July 24, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Russian State Hackers Exploit Zimbra Zero-Click Zero-Day | CRITICAL |
|
5 C2 IPs | 79 OTX IOCs | 34 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is dominated by active zero-day exploitation, notably a newly disclosed Check Point vulnerability (CVE-2026-16232) and a Russian state-sponsored campaign by Laundry Bear exploiting a zero-click Zimbra flaw to steal emails. Additionally, emerging threats target AI ecosystems, including a sandbox escape in Anthropic's Claude Cowork and the "AgentForger" flaw in OpenAI's ChatGPT. Cybercriminals are also leveraging AI for target profiling (Dolphin X) and abusing legitimate platforms like GitHub Actions and Notepad++ plugins for malware delivery. |
|
■ CRITICAL STORIES New Check Point Zero-Day Vulnerability CVE-2026-16232 Exploited in the Wild Attackers are actively exploiting a newly disclosed zero-day vulnerability in Check Point Security Gateways, requiring immediate remediation. |
Russian Espionage Group Laundry Bear Exploits Zimbra Zero-Day A Kremlin-backed group used zero-click phishing and JavaScript injection to compromise Zimbra webmail servers globally, stealing emails and 2FA codes. |
Claude Cowork Sandbox Escape Allows Host File Access Researchers discovered a critical sandbox escape vulnerability in Anthropic's Claude Cowork, allowing an AI agent to escape its Linux VM and access files on host macOS systems. |
OpenAI Fixes "AgentForger" Flaw in ChatGPT A vulnerability in ChatGPT allowed attackers to create and remotely control invisible, autonomous AI agents inside victim organizations. |
|
■ CVEs IDENTIFIED CVE-2026-16232 Check Point Security Gateway — Zero-day vulnerability exploited in the wild against specific customer configurations. |
[CVE-TBD] Zimbra Collaboration Suite — Zero-click JavaScript injection vulnerability exploited by Laundry Bear to steal emails and 2FA codes. |
[CVE-TBD] Anthropic Claude Cowork — Sandbox escape vulnerability allowing Linux VM breakout to access host Mac files. |
[CVE-TBD] OpenAI ChatGPT — AgentForger vulnerability allowing unauthorized creation and control of invisible autonomous AI agents. |
|
■ THREAT ACTORS Laundry Bear (Void Blizzard) | State-sponsored (Russia) |
Exploited Zimbra zero-day via zero-click phishing to steal 90 days of emails and 2FA codes. |
JadeProx | State-sponsored (China) |
Targeted government, healthcare, and education in Asia and Latin America using TriBack Loader. |
Chaos Ransomware Group | Cybercrime |
Deployed msaRAT to route C2 traffic through headless Chrome and Edge browsers. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploitation of Check Point CVE-2026-16232 and Zimbra zero-day. |
| T1566.002 | | Spearphishing Link | Zero-click phishing used by Laundry Bear to inject malicious JavaScript. |
| T1574.012 | | DLL Side-Loading | Abuse of Notepad++ plugins to load the LunchPoke malware. |
| T1071.001 | | Web Protocols | Routing C2 traffic through headless Chrome/Edge browsers via msaRAT. |
| T1588.002 | | Tool | Use of Dolphin X malware utilizing AI-powered profiling to rank high-value targets. |
| T1110.004 | | Credential Stuffing | Automated attacks against Chick-fil-A One accounts. |
|
■ PATCH PRIORITY Check Point — CVE-2026-16232 zero-day exploited in the wild — SecurityWeek |
Zimbra — Zero-click zero-day exploited by Russian state actors — CISA / Unit 42 |
Adobe — HermeticReader Acrobat extension vulnerability — Malwarebytes |
Anthropic — Claude Cowork sandbox escape — The Hacker News |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch Check Point Security Gateways immediately to remediate the actively exploited CVE-2026-16232 vulnerability. |
| 2 | [P1] Apply the latest security patches to Zimbra Collaboration Suite to block the zero-click JavaScript injection exploits used by Laundry Bear. |
| 3 | [P1] Update the Adobe Acrobat Chrome Extension to the latest version to mitigate the HermeticReader vulnerability. |
| 4 | [P2] Update Anthropic Claude Cowork to ensure the sandbox escape vulnerability is resolved. |
| 5 | [P2] Implement application whitelisting and monitor Notepad++ plugin directories (e.g., %APPDATA%\Notepad++\plugins) for unauthorized DLLs. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |