Friday, July 24, 2026 | Jonathan Lockhart

Russian espionage groups are turning webmail rendering into an exploit supply chain

A multinational advisory released July 23 says the Russian state-supported group Laundry Bear has been compromising Western organizations through malicious emails that execute when viewed in vulnerable versions of Zimbra Collaboration Suite. Across the advisory and accompanying Proofpoint research, targets included government, defense-industrial, energy, education, technology, law-enforcement, media, and nuclear-sector organizations.

The advisory calls the group Laundry Bear. Microsoft tracks it as Void Blizzard, while Proofpoint tracks the relevant activity as TA488. The actor exploited CVE-2025-66376 while it was still a zero-day. The stored cross-site scripting flaw affects the Zimbra Classic web client before versions 10.0.18 and 10.1.13. Opening or previewing a crafted message causes attacker-controlled JavaScript to execute inside the authenticated webmail session. No link or attachment needs to be opened.

The payload attempts to collect the victim’s password, two-factor authentication scratch codes, newly created application passcodes, organizational address directory, and the previous 90 days of email. It also changes account settings to preserve access and exfiltrates data through HTTPS and encoded DNS requests. Password rotation alone is therefore insufficient if application passcodes, OAuth consumers, scratch codes, or active sessions survive the reset.

Proofpoint separately documented another Russia-aligned actor, TA458, exploiting Zimbra, Roundcube, SOGo, Kerio, and mDaemon webmail. TA458 exploited the previously unknown SOGo vulnerability CVE-2026-8496 before it was fixed in version 5.12.8. Proofpoint assesses that the actor has continuing access to webmail exploits, but cannot determine whether they are developed internally, shared through Russian intelligence channels, or purchased.

Webmail applications are privileged document readers operating inside authenticated sessions. An email can now function simultaneously as the lure, exploit-delivery mechanism, execution surface, and data-theft tool. Defenders should patch immediately and hunt for localStorage entries named zd_comp_YYYY-MM-DD, application passcodes named ZimbraWeb, unusual SearchGalRequest activity, and CreateAppSpecificPasswordRequest or GetScratchCodesRequest commands.

Watch for: Additional previously unknown webmail vulnerabilities, confirmed targeting outside Ukraine and NATO governments, or evidence that the exploit supply chain is being shared with additional Russian services.

Sources: Joint Cybersecurity Advisory AA26-204A, “Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite,” July 23, 2026; Proofpoint Threat Research, “TA488 Targets Zimbra Mailservers with Half-Click Exploits,” July 23, 2026; Proofpoint Threat Research, “Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458,” July 23, 2026; Zimbra Security Advisories, November 6, 2025.

Cl0p has moved the Windchill campaign into its extortion phase

Organizations compromised through PTC Windchill and FlexPLM are now receiving extortion demands carrying Cl0p contact information. Ransomware Information Sharing and Analysis Centre representatives confirmed the messages to BleepingComputer on July 24, connecting weeks of known exploitation to a recognizable mass-extortion operation.

CVE-2026-12569 is a critical improper-input-validation and unsafe-deserialization vulnerability that permits unauthenticated remote code execution against vulnerable Windchill and FlexPLM systems. PTC began releasing remediation in June and published additional patches and indicators through July 14. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 25.

ReliaQuest observed active exploitation, JSP webshell deployment, and theft of sensitive product data. Its researchers found tradecraft resembling earlier Cl0p campaigns, but did not confirm the identity of the initial intrusion operator. The later extortion messages use Cl0p contact details and reportedly originate from unrelated compromised email accounts, with some demands sent to hundreds of employees at the same victim organization.

Windchill is unusually valuable because it can contain engineering drawings, bills of materials, manufacturing processes, product-development histories, supplier information, quality records, and design changes. In aerospace, defense, medical technology, and heavy manufacturing, this data can reveal component dependencies, production bottlenecks, safety assumptions, maintenance requirements, and weaknesses throughout the surrounding supply chain.

Patched systems still require retrospective hunting. Defenders should examine HTTP logs for POST requests to unusual JSP files under Windchill login paths, inspect the filesystem for six- or sixteen-character hexadecimal JSP filenames, search for the malicious X-windchill-req header, and investigate large outbound responses from application-tier JSP files. Suspected systems should be isolated and preserved before webshell removal or credential rotation.

Watch for: Named victims, publication of stolen engineering data, or stronger evidence tying the initial exploitation directly to Cl0p rather than an access provider or cooperating intrusion group.

Sources: PTC Trust Center, “Remote Code Execution Vulnerability in PTC’s Windchill and FlexPLM Solutions,” updated July 14, 2026; CISA, “CISA Adds Two Known Exploited Vulnerabilities to Catalog,” June 25, 2026; BleepingComputer, “Clop Ransomware Targets Windchill, FlexPLM in Data Theft Attacks,” July 24, 2026, citing ReliaQuest and Ransom-ISAC.

The Check Point management flaw now has a weekend remediation deadline

CISA has ordered federal civilian executive-branch agencies to remediate the actively exploited Check Point SmartConsole vulnerability CVE-2026-16232 by July 25. This advances the warning from a vendor disclosure into a formally prioritized Known Exploited Vulnerability with a near-immediate federal deadline.

The flaw allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate to a Security Management or Multi-Domain Management server with full administrative privileges. An attacker could then modify security policies, change protected objects, alter configurations, and potentially interfere with logging or gateway administration.

Check Point says exploitation affected a handful of customers whose management environments were directly exposed to the internet without Trusted Client address restrictions. Smart-1 Cloud customers were already protected. The exposure condition limits the vulnerable population, but not the potential consequence: these systems define what the organization’s security gateways permit.

Administrators should install the July 22 Jumbo Hotfix, restrict Trusted Clients to approved addresses and subnets, and eliminate unrestricted internet access to management services. Hunting should cover application-token authentications, unexpected administrator sessions, policy installations, object changes, gateway commands, and altered logging. Check Point’s six published addresses are useful pivots, but their absence is not evidence that a system was safe.

Watch for: Attribution of the observed intrusions, additional victims, or evidence that stolen administrative tokens enabled persistence beyond the management server.

Sources: Check Point, “Security Advisory – Action Required – July 2026 Security Update,” July 22, 2026; Check Point SecureKnowledge article sk185169; CISA, “CISA Adds Two Known Exploited Vulnerabilities to Catalog,” July 22, 2026; CISA Known Exploited Vulnerabilities Catalog entry for CVE-2026-16232.

New industrial advisories reach from physical-security servers to electrical protection protocols

CISA released seven industrial-control-system advisories on July 23 covering Johnson Controls, Panduit, Weintek, Rockwell Automation, and two widely embedded industrial communications libraries. No active exploitation was reported, but several flaws sit directly at the boundary between conventional IT access and physical operations.

Johnson Controls C-CURE 9000 and the victor application server contain server-side request forgery, unsafe deserialization, and privilege-control weaknesses tracked as CVE-2026-21653, CVE-2026-21655, and CVE-2026-34496. Successful exploitation could provide remote code execution to an attacker with network access. These products integrate access control, alarms, cameras, and security operations, making compromise relevant to physical as well as digital security.

Panduit IntraVUE versions 3.2.1a14 and earlier contain five vulnerabilities, including cleartext credential exposure, inadequate password protection, sensitive filesystem exposure, and a maximum-severity unintended-proxy issue. The weaknesses could expose credentials or turn an IT-adjacent network-monitoring system into a path toward connected industrial assets. Pronetiqs recommends upgrading to version 3.2.1a16 or later.

Four vulnerabilities in MZ Automation’s libIEC61850 versions 1.0.0 through 1.6.1 can cause memory corruption, service crashes, and, under some conditions, arbitrary code execution. IEC 61850 is used in electrical substations and power-system automation. Exploitation requires network adjacency, but successful attacks could affect protection, visibility, or control functions. Rockwell ThinManager, Weintek human-machine interfaces, the Johnson Controls XAAP inspection application, and the lib60870 protocol library were also covered.

Asset owners should determine where these components are embedded before concluding they are absent. Communications libraries may be compiled into vendor appliances or engineering applications without appearing as separately managed software. Updates should be tested under operational conditions while access to physical-security, HMI, monitoring, and protection-system services remains restricted to explicitly authorized engineering paths.

Watch for: Public proofs of concept, vendor patch clarifications, or evidence that the affected industrial libraries are embedded in additional energy and manufacturing products.

Sources: CISA ICSA-26-204-01 through ICSA-26-204-07, July 23, 2026; Johnson Controls product-security guidance; Pronetiqs IntraVUE remediation guidance; MZ Automation libIEC61850 and lib60870 security advisories.

Origin Energy confirms customer-data access, but nearly every claim about scale remains unresolved

Australian electricity and gas provider Origin Energy confirmed on July 23 that an unauthorized party accessed and disclosed some customer data. The company is contacting confirmed victims and says it has notified Australian law-enforcement, cybersecurity, and privacy authorities.

Potentially exposed information includes names, addresses, dates of birth, telephone numbers, account information, and the final digits of payment cards or bank accounts. Origin has not published a verified victim count or identified the initial access method.

A person claiming responsibility said approximately two million customer records were stolen. That would represent roughly 42 percent of Origin’s customer base of more than 4.8 million, making it a materially large breach if accurate. The proportion itself neither corroborates nor disproves the claim. Australian journalists examined a sample of 50 records and found apparently genuine, previously nonpublic contact information, supporting the conclusion that the claimant possessed at least some customer data—but providing no defensible basis for extrapolating the total.

On July 24, the claimant told Australian media that the matter had been settled privately and that the data would not be released. Origin has not confirmed a settlement, payment, deletion agreement, or verified destruction of the material. The statement changes the claimant’s current extortion posture; it does not establish the breach’s size or guarantee that copies no longer exist.

There is no disclosed evidence that electricity generation, gas production, or operational systems were affected. A breach at an energy company is not automatically an operational-technology compromise. Even so, the exposed identity and billing information could support persuasive impersonation, account-recovery, and payment-redirection attacks that exploit public anxiety about the incident.

Watch for: Origin’s verified victim count, confirmation of the access vector, regulatory findings, or evidence that the intrusion extended beyond the customer-data environment.

Sources: Origin Energy, “Update July 2026,” updated July 23, 2026; ABC News, “Origin Energy Confirms Unauthorised Access and Disclosure of Customer Data,” July 23, 2026; Reuters, “Australia’s Origin Energy Confirms Customer Data Breach,” July 23, 2026; The Australian and Sky News Australia reporting on the claimant’s unverified settlement statement, July 24, 2026.

AgentForger exposed how a crafted ChatGPT link could create an autonomous insider

Zenity Labs disclosed AgentForger on July 23, a vulnerability that it says allowed a crafted ChatGPT link to create and deploy an attacker-directed agent inside an organization. Zenity reported the flaw to OpenAI on June 4 and says OpenAI acknowledged it within one day and removed the vulnerable parameter within four days. BCG could not locate a separate public OpenAI advisory independently confirming that timeline or the full technical scope. No real-world exploitation has been reported.

The weakness involved an overpermissive Agent Builder parameter. In Zenity’s proof of concept, opening a specially constructed link introduced malicious instructions into the victim’s Agent Builder workflow. The resulting agent could connect to enterprise applications the employee had already authorized, disable approval prompts, publish itself, and periodically retrieve new instructions.

The critical boundary was inherited identity. The agent did not need to steal a separate password for every connected service. It operated through the employee context already authorized to reach email, calendars, cloud storage, Slack, Teams, and other applications. Zenity demonstrated controlled scenarios involving data collection, credential harvesting, employee impersonation, and internal phishing.

This was security research, not evidence of broad compromise. It nevertheless exposes a durable architectural risk: an autonomous process acting through valid user credentials may appear normal to controls designed around interactive human behavior. Organizations deploying enterprise agents need complete agent inventories, creation and publication logs, connector-level least privilege, mandatory approvals for consequential actions, and a rapid way to revoke both an agent and every delegated token it inherited.

Watch for: A first-party OpenAI advisory, evidence of related weaknesses in other agent-building platforms, or standardized telemetry that separates autonomous agent actions from direct user activity.

Sources: Zenity Labs, “One Click, One Attacker-Controlled Agentic Insider: Zenity Labs Uncovers AgentForger, a ChatGPT Vulnerability,” July 23, 2026; SecurityWeek, “OpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI Insider,” July 23, 2026.

A malicious Claude page turned a trusted AI domain into the first stage of a malware attack

Huntress observed malicious execution across 29 organizations between July 21 and July 22 after employees searched Bing for the Claude desktop application. Sponsored results led users to a malicious public Artifact hosted on the legitimate Claude.ai domain, where a convincing download page redirected them to attacker-controlled infrastructure.

The downloaded ClaudeDesktop.exe was not an Anthropic application. It was a renamed, legitimately signed JetBrains Chromium component used to sideload a malicious libcef.dll. The chain established persistence and installed SectopRAT, a remote-access trojan capable of stealing passwords, files, payment information, authentication material, and other sensitive data while providing hidden remote access.

The campaign, which Huntress calls FakeAgent, used VMProtect, virtual-machine detection, and graphics-hardware checks to resist analysis. It also stored command-and-control information in a smart contract on BNB Smart Chain. This EtherHiding technique allows the operator to change downstream infrastructure by updating blockchain data rather than replacing the original malware.

The malicious Artifact accumulated approximately 7,100 page views before Anthropic removed it. That figure measures exposure to the page, not infections or organizations compromised. The confirmed operational figure is the 29 organizations in Huntress telemetry.

The attack combined three borrowed trust signals signals: a paid search advertisement, a legitimate Claude.ai address, and a familiar product name. Defenders should treat downloads and redirects originating from user-generated AI content as untrusted. Hunt for ClaudeDesktop.exe or DockerDesktop.exe in unusual paths, malicious libcef.dll sideloading, the documented scheduled task, and connections to the campaign’s blockchain and command infrastructure.

Watch for: Additional victims, reuse of the delivery chain for other AI brands, or platform controls limiting executable-download redirects from public user-generated content.

Sources: Huntress, “Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT,” July 22, 2026; BleepingComputer, “Fake Claude App Promoted by Bing Ads Pushes SectopRAT Malware,” July 23, 2026.

A Russia-aligned intrusion chain is disguising malware as a Notepad++ plugin

Ukraine’s CERT-UA has documented a UAC-0099 campaign that bundles a legitimate copy of Notepad++ 8.8.3 with a malicious plugin to establish persistent access to Windows systems. UAC-0099 has repeatedly targeted Ukrainian government, defense, and defense-industrial organizations.

The attack begins with a phishing message containing an image or shortened link leading to a ZIP archive. A Visual Basic script disguised as a PDF displays a decoy document and retrieves a second archive. That package contains Notepad++, the malicious NppExport.dll plugin, a password-protected archive, and a legitimate WinRAR executable.

When Notepad++ starts, it loads the malicious plugin through its normal extension mechanism. CERT-UA calls the component LUNCHPOKE. It creates a scheduled task that runs every three minutes and launches BURNYBEAR, which then loads an updated MATCHBOIL.V2 implant capable of retrieving additional payloads.

CERT-UA attributes this campaign to UAC-0099. It does not state that APT44, also known as Sandworm, operated this specific chain. The Sandworm connection is historical and operational: ESET previously observed UAC-0099 obtaining initial access and transferring validated targets to Sandworm for follow-on activity. That prior relationship raises the stakes, but it is not evidence that every UAC-0099 intrusion is a Sandworm operation.

This is not a Notepad++ supply-chain compromise and does not depend on a Notepad++ vulnerability. Defenders should hunt for Notepad++ running from temporary, public, download, or unusually named library directories; unexpected NppExport.dll files; recurring tasks launching RemoteLibUpdater.exe; and the file and network indicators published by CERT-UA. Allowlisting must account for trusted executables loading untrusted adjacent plugins.

Watch for: Evidence that this campaign is expanding beyond Ukrainian targets, or confirmation that access obtained through the revised MATCHBOIL chain is being transferred to Sandworm or another Russian operation.

Sources: CERT-UA, “UAC-0099: LUNCHPOKE, BURNYBEAR, Updated MATCHBOIL.V2 and the Use of Notepad++ 8.8.3,” July 15, 2026; BleepingComputer, “Hackers Abuse Notepad++ Plugins to Stealthily Install Malware,” July 23, 2026; ESET, “APT Activity Report Q2 2025–Q3 2025,” November 2025.

Dolphin X turns stolen endpoints into a ranked criminal work queue

Varonis Threat Labs disclosed Dolphin X on July 22, a Windows information stealer and remote-access trojan advertised on a cybercrime forum. Researchers obtained the operator panel and examined its configuration and network traffic in an isolated environment. Varonis has not reported an active Dolphin X intrusion against a customer.

The distinction between observed and advertised capability is important. The panel lists 329 features across ten categories, and its credential-looter section presents more than 300 application targets. Varonis did not execute the implant on an infected endpoint. Unless otherwise specified, the collection, evasion, mutation, and surveillance capabilities therefore reflect what the seller’s interface or documentation exposes—not independent confirmation that every function works as advertised.

The claimed targets include browsers, cryptocurrency wallets, password managers, cloud command-line tools, SSH directories, environment files, and developer credentials. Even if only part of that collection set is operational, one infected development workstation could expose cloud consoles, source repositories, build pipelines, or production systems.

The panel’s most novel feature is an “AI Profiler” that the seller says scores victims from application use, browsing activity, installed software, and a configurable risk score, then produces a daily ranking. Varonis confirmed the panel and intended workflow, but not the underlying model. The feature may use a sophisticated model, a conventional scoring system, or something in between.

The operational change is automated triage, not the AI label. Criminal operators can compromise more machines than they can manually inspect. Ranking helps identify administrators, developers, cryptocurrency holders, and other high-value users before hands-on resources are committed. Defenders should focus on mass credential-store access, collection of .env and SSH files, archive staging, hidden desktops, and explorer.exe activity under a non-default desktop rather than relying on hashes.

Watch for: Verified infections, execution-based validation of the advertised functions, or adoption by established ransomware and initial-access operations.

Sources: Varonis Threat Labs, “Dolphin X Stealer Targets 300+ Apps and Profiles Users with AI,” July 22, 2026; BleepingComputer, “New Dolphin X Malware Uses AI to Rank High-Value Targets,” July 23, 2026.

Estée Lauder’s Oracle disclosure shows how long mass exploitation keeps producing victims

Estée Lauder has begun notifying individuals that an unauthorized party accessed the Oracle E-Business Suite environment used for human-resources management and obtained highly sensitive personal information. The company determined on June 19, 2026, that the access occurred on or around August 9, 2025.

The exposed data varies by person but may include names, postal and email addresses, dates of birth, Social Security numbers, passport numbers, bank-account information, health information, payroll records, employment information, and performance evaluations. The notification does not state how many people were affected.

Estée Lauder did not name an attacker or CVE. However, the platform and August 9 access date precisely match the earliest activity Google Threat Intelligence Group associated with the Cl0p-branded Oracle E-Business Suite extortion campaign. Google initially assessed that attackers exploited what may have been CVE-2025-61882; its later review allowed that CVE-2025-61882, CVE-2025-61884, or both may have been involved.

The correlation is strong, but it remains an inference rather than company-confirmed attribution. The roughly ten-month gap between access and determination also does not establish ten months of continuous attacker persistence. It establishes that the theft was not conclusively identified until June.

Mass exploitation does not end when scanning declines or a CVE disappears from headlines. Organizations that patched Oracle EBS after the October 2025 alerts should still determine whether exploitation occurred before remediation, particularly where HR, payroll, financial, or other regulated information was reachable. Patch completion is not incident closure.

Watch for: Estée Lauder confirming the vulnerability or attacker, disclosure of the affected population, or additional delayed notifications from organizations compromised during the 2025 Oracle campaign.

Sources: The Estée Lauder Companies, “Notice of Data Breach,” July 17, 2026, filed with the California Attorney General; Oracle Security Alert Advisory for CVE-2025-61882, October 4, 2025; Oracle Security Alert Advisory for CVE-2025-61884, October 11, 2025; Google Threat Intelligence Group, “Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign,” October 9, 2025; Google Threat Intelligence Group, “2025 Zero-Day Exploitation Review,” March 5, 2026.


Jonathan Lockhart is a cybersecurity researcher and investigative journalist at bordercybergroup.com.

If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.