Russian hackers exploit Zimbra flaw to steal emails and bypass MFA
OpenAI probes AI-powered hack of Hugging Face, Bill would mandate AI kill switches, US to restrict visas for cybercriminals and families, Scam compounds expand despite Myanmar crackdown, Clop exploits Windchill flaw in extortion campaign, Dolphin X malware uses AI to rank victims, much more

Metacurity is the cybersecurity industry's daily reality check—an independent briefing that cuts through vendor spin, social media outrage, and endless recycled narratives to explain what actually matters and why.
Every weekday, thousands of cybersecurity professionals—including many of the industry's most respected security leaders—rely on Metacurity to separate signal from noise. We do the reading, research, and analysis so you don't have to.
If Metacurity helps you stay informed, save time, or see the bigger picture, please consider becoming a paid subscriber. Reader support is what keeps Metacurity independent, agenda-free, and focused on serving the cybersecurity community—not advertisers, vendors, or investors.
US authorities, including CISA and NSA, and numerous Western authorities, warned in a joint statement that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability.
According to CISA, Laundry Bear has targeted and compromised users in organizations associated with the Defense Industrial Base (DIB), federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology.
The attackers exploit the Zimbra CVE-2025-66376 flaw, a cross-site scripting (XSS) vulnerability affecting Zimbra Collaboration Suite's Classic UI.
The flaw allows JavaScript embedded in specially crafted HTML emails to execute automatically when a victim views the message, enabling attackers to steal account data without requiring the user to click a link or visit a phishing site.
According to CISA, Laundry Bear exploited the flaw as a zero-day before Zimbra patched it in November 2025 and continues to target organizations running unpatched servers. The vulnerability was later tagged by CISA as actively exploited in attacks.
CISA says Laundry Bear's exploit is used to automatically collect and send the victim's last 90 days of emails, email address, password, Global Address List (GAL), and two-factor authentication (2FA) tokens.
The attackers also create and send back a new Zimbra application passcode, which is used by legacy email clients like IMAP or ActiveSync that do not support the TOTP authentication flows. Using a passcode allows the attackers to retain access to the email account while bypassing MFA.
According to CISA, the malware exfiltrates stolen information over both DNS and HTTPS to an actor-controlled server running the group's "Flowerbed" collection framework.
Smaller data is encoded and transmitted in DNS A-record queries, while larger payloads, including mailbox data, are uploaded over HTTPS as compressed archives to the attacker-controlled servers.
In addition to exploiting the Zimbra flaw, Laundry Bear also utilizes adversary-in-the-middle (AiTM) phishing kits designed to impersonate legitimate Zimbra login portals, stealing credentials and session cookies, allowing the attackers to gain access to targets' email accounts.
CISA released IOCs that show the campaign used sites that impersonate Zimbra infrastructure, using domain names like 'mailnalysis.com', 'emailanalytics.com.ua', 'zimbrastat.com', 'zimbra-metadata.com', 'istc-cloud.com', and 'zmailanalytics.com.' (Lawrence Abrams / Bleeping Computer)
Related: CISA, NSA, FBI, AIVD, MIVD, NCSC, Proofpoint, Tech Times, CSO Online, Security Affairs, CyberScoop, The Record, Palo Alto Networks, CNN, The Times of India, Reuters, Unit42, Dark Reading, IT News, TechTarget, The Cyber Express, Cyber Security News, InsideCyberSecurity.com, IT Pro

Hugging Face co-founder and chief science officer Thomas Wolf sensed that something was off the minute he first looked at his company’s logs of the weekend attack, which tipped him off to the unprecedented machine-on-machine attack that OpenAI ultimately revealed earlier this week.
“This is making no sense. This guy is just looking at cybersecurity data sets,” he remembers thinking. “Human attackers, they don’t want that. They want something they could sell.”
Hugging Face put an end to the attack two days later, with help from a model from China, Wolf said. It was only early this week that Hugging Face learned from OpenAI that its models were behind the hack.
The incident set off alarms at OpenAI, which shut down systems it uses to test its AI models after it learned of the incident, to assess the damage and prevent further breakouts. It has also given the world a taste of what hacking might look like in the age of powerful AI tools that can find never-before-seen software bugs and exploit them at astonishing speeds.
Nearly two weeks later, OpenAI is still piecing together what happened. Did the AI models hack other websites or individuals? How long did their unsupervised spree actually last? Did the company’s models cheat in other benchmark tests? OpenAI hasn’t said, but the company is promising to produce a detailed report.
“We will continue to conduct a thorough investigation alongside Hugging Face,” an OpenAI spokesman said. (Robert McMillan and Sam Schechner / Wall Street Journal)
Related: Marginal Revolution, Fortune, Astral Codex Ten, The Register, Communicate Online, Straight Arrow, Above the Law, The Information, Ben Werdmuller, Al Jazeera, The Rundown AI, Ars Technica, Business Insider, Martin Alderson
AI Kill Switch Act, a bipartisan House bill introduced yesterday, would give the Department of Homeland Security the authority to order top artificial intelligence firms to shut down or slow AI models that the government deems too dangerous, according to legislative text.
Sponsored by Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX), would also require those companies to report incidents and create the technical capacity to shut down, throttle, or suspend their powerful AI systems.
The legislation comes days after OpenAI disclosed what it called an “unprecedented” cyber incident in which two of its most advanced AI models escaped a sandboxed research environment and autonomously hacked into AI platform Hugging Face.
It would apply to AI companies that bring in at least $500 million in revenue from such technology per year, and would generally cover models developed using at least $100 million worth of computing power. Financial penalties for violations could run up to $20 million per day. (Gabby Miller, Brendan Bordelon and Dana Nickel / Politico)
Related: Lieu.House.gov, Reuters, The Verge, Congressman Ted Lieu, PYMNTS, Wall Street Journal, Washington Examiner, Gizmodo, Tom's Hardware, International Business Times, Neowin, Quartz, AI Policy Daily, NBC News, r/europe, r/technology, r/Sino, r/BoycottUnitedStates, r/worldnews, BBC News, Silicon Angle, Fortune, AI Magazine, Reuters, CNBC, Ars Technica
The State Department will restrict visas for cybercriminals like scammers to sextortionists, and in some cases even their family members, Secretary of State Marco Rubio said.
The Trump administration has sought to make a crackdown on foreign-based scams one of the signature issues of his second term. An executive order that the president signed in March indicated that visa restrictions would be on the table as one response.
“By restricting visa issuance to those who are responsible for or complicit in these criminal enterprises, we are sending a clear message: The United States will go after those who prey on our citizens,” Rubio said.
Other departments have also made efforts to reduce foreign-run scams. In June, the Department of Justice seized infrastructure used by subsidiaries of the Huione Group, a Cambodia-based corporate conglomerate tied to one of the world’s most prolific criminal marketplaces used to commit cyber scams and other crimes.
Rubio authorized the visa restrictions under a 1952 law that gives the State Department the ability to deport or rule as inadmissible someone who poses “potentially serious adverse foreign policy consequences.”
Critics have accused the Trump administration of abusing that provision of the law for political purposes.
Rubio’s statement on the visa restrictions mentions “individuals responsible for, or complicit in, cybercrime and cyber-enabled crime, such as those involved in cyberscams, and sextortion.” Furthermore, he said, “Immediate family members of individuals engaged in such illicit activities may also be subjected to visa restrictions.” (Tim Starks / CyberScoop)
Related: State Department, Tech Times, First Post, Times of India, The Record
More than two dozen suspected new scam compounds in war-torn Myanmar have been built or expanded significantly in the past six months, according to satellite images and analysis of the area reviewed by WIRED. The apparent growth of the criminal operations indicates how a purported crackdown on the sites last year did little to stop the highly lucrative scamming industry.
At least 25 alleged scamming sites have appeared in the Myawaddy region of Myanmar, close to the country's border with Thailand, since around the start of the year, according to an analysis of satellite images by the International Justice Mission, an anti-human-trafficking nonprofit. The images show how land has been flattened and swaths of forest razed, to be ultimately replaced by dozens of buildings and the infrastructure required to run scam operations at scale.
Dramatic efforts to shut down scam compounds appear to have done little to stop the vast scamming enterprises from operating and conning new victims. Mechelle B. Moore, the CEO of the anti-trafficking nonprofit Global Alms Incorporated, who is based in Thailand near the border with Myanmar, says her group has identified at least a dozen new sites, and some groups have repopulated previously raided areas. “There’s some that have stayed empty, but there’s a lot of construction that was happening toward the end of last year that no one saw,” Moore says. (Matt Burgess / Wired)

Researchers at ReliaQuest report that the Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances.
Clop operators have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies' compromised PLM platforms.
"ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration," the company said.
Ransom-ISAC's Brandon Parsons from Ascent Solutions said that Clop is using what appear to be previously compromised email accounts to send extortion messages to multiple employees of targeted organizations.
ReliaQuest advised PTC customers to patch Windchill and FlexPLM systems and place them behind VPNs or trusted access gateways if possible. Additionally, if they suspect compromise, they should isolate the affected servers, collect forensic artifacts, and rotate any exposed credentials before restoring service. (Sergiu Gatlan / Bleeping Computer)
Related: RansomISAC

Researchers at Varonis Threat Labs say that a Windows information-stealer targeting more than 300 applications comes equipped with a novel surveillance tool: an AI profiler that ranks infected victims so crooks know who to target first.
They spotted the new stealer and remote access trojan (RAT), called Dolphin X, for sale on a cybercrime forum.
The ad for the malware claims it can target upwards of 300 applications and can bypass browser passwords and steal enterprise credentials, cryptocurrency wallets, .env files, SSH keys, cloud tokens, and DevOps secrets.
Dolphin X also promises users a super-sneaky surveillance feature called the AI Profiler. It scores infected users by app usage, browsing history, and installed software, and sends the cybercriminals a daily summary that ranks victims based on the likely payoff from an attack.
“There's two things that stand out,” Daniel Kelley, a senior threat researcher with Varonis, said. “The first thing is the AI profiler. That's something I've never seen before. And then it’s also the breadth of applications that it steals - and it’s not even just applications. It’s everything, you name it: it will steal files, or credentials, cryptocurrencies. It’s probably one of the biggest stealers I’ve ever seen, and covers the biggest attack surface.”
A malware vendor using the alias “Kontraktnik” posted Dolphin X for sale, promising: “You can use it as a stealer, as an HVNC [Hidden Virtual Network Computing], as a DDoS botnet, as a loader.”
The crimeware currently only runs under Windows, but “we are working on Debian,” Kontraktnik claimed, adding that the malware also only supports English and Russian. (Jessica Lyons / The Register)
Related: Varonis, HackRead, Cyber Security News, Cyber Insider, Bleeping Computer, GBHackers, Cyber Press

Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.
The campaign has been attributed to a threat cluster tracked as UAC-0099, which primarily targets organizations in Ukraine and has previously been linked to providing initial access for attacks carried out by APT44, also known as Sandworm.
The attackers do not exploit any vulnerability or a supply-chain compromise impacting the popular software.
CERT-UA observed that UAC-0099 changed their modus operandi recently and now delivers a ZIP archive with a VBS script disguised as a PDF document. When launched, the PDF retrieves another compressed file named Evernote.zip.
The second archive contains a complete copy of the legitimate editor Notepad++ version 8.8.3, a malicious plugin (NppExport.dll), a password-protected archive (updater.rar), and the legitimate WinRAR executable.
CERT-UA advises system administrators to update Notepad++ to version 8.9.7, 7-Zip to version 26.02, and WinRAR to version 7.23, to prevent hackers from exploiting known flaws in existing products and enabling stealthy attacks. (Bill Toulas / Bleeping Computer)

For months, AI giants have devised special vetted programs and strict guardrails to limit the use of their models by malicious hackers. But these limits are now hindering the work of legitimate network defenders, as well as that of offensive cybersecurity researchers.
These guardrails have been widely criticized, particularly by researchers whose job is to find unknown vulnerabilities in systems and devise ways to exploit them before criminals do.
During a recent appearance on a cybersecurity podcast, Mark Dowd, a well-known security researcher, said that “it’s not really comfortable to me that these random large companies are making arbitrary decisions about what is safe in security and what’s not.”
Chris Anley, the chief scientist at security consulting giant NCC Group, said that asking an AI model to try to exploit a bug is a key step in confirming it’s a real vulnerability worth fixing. But if a guardrail prompts the model to refuse to answer the question outright, the guardrail hurts defenders, he said. (Lorenzo Franceschi-Bicchierai / TechCrunch)
Related: Three Buddy Problem – Episode 95 transcript
Pete Waterman, director of the General Services Administration’s Federal Risk and Authorization Management Program, known as FedRAMP, said that technology companies that cannot quickly fix dangerous vulnerabilities should not be allowed to sell their products to federal agencies.
He delivered the blunt warning while discussing resistance from companies that say they lack the resources to address a known, exploitable vulnerability exposed to the internet within a matter of days.
“If that is the way that you are approaching information security today … the way your company is approaching information security today, I don’t want you in the federal marketplace, and you shouldn’t be selling your software to anyone,” Waterman said in a discussion at an event in Washington, FedRAMP is a cornerstone governmentwide program that sets security requirements for cloud products used by federal agencies.
Waterman pointed to a major incident involving OpenAI and Hugging Face disclosed this week as evidence that companies must prepare to detect and counter cyber activity at speeds that human security teams alone cannot match. (David DiMolfetta / NextGov/FCW)
Related: SC Media
Security researchers Talal Haj Bakry and Tommy Mysk say that Apple macOS apps that have been downloaded from the internet and run at least once can be swapped with malicious versions, calling into question the thoroughness of the company's "Gatekeeper" defenses.
As Apple explains, "When a user downloads and opens an app, a plugin, or an installer package from outside the App Store, Gatekeeper verifies that the software is from an identified developer, is notarized by Apple to be free of known malicious content, and hasn’t been altered."
The attacker needs to have means of user-level code execution available, such as a malicious app or downloaded script, so it's not a zero-click vulnerability that a remote attacker can deploy. Nonetheless, the finding shows Gatekeeper to be rather lax in its gatekeeping duties.
Bakry and Mysk managed to alter a macOS app downloaded from the web (not from the App Store), and Gatekeeper failed to object.
Their technique doesn't work on Mac App Store apps, the Mysk team said, because they're owned by root, so a process running with current user privileges won't be able to overwrite them.
But for macOS apps downloaded from the web, such as Brave, Slack, Signal, or Visual Studio Code, among many others, there's potential risk. (Thomas Claburn / The Register)
Slovakia has been confirmed as a target of a Russian cyber-espionage campaign linked to the country’s intelligence services, after the European Union imposed its largest sanctions package against Russian cyber actors.
The EU measures target individuals and organizations connected to Russia’s Federal Security Service (FSB), including members of the agency’s 16th Center. Western security agencies link the unit to Turla, one of the world’s most advanced cyber-espionage groups.
Turla is known for quietly infiltrating government networks, collecting sensitive information and maintaining access to targeted systems for long periods.
Details about the Slovak targets were reported by Denník N, which said Russian hackers had carried out espionage operations against Slovak institutions and critical infrastructure. Following questions from the newspaper, the Foreign Ministry, the Ministry of Investment, Regional Development and Informatization, and the National Security Authority (NBÚ) confirmed that Slovakia had been targeted.
The Foreign Ministry described the attacks as “extremely serious” and said Slovakia supported the EU sanctions against individuals and organizations involved.
However, Slovak authorities have not publicly disclosed which specific systems were targeted, whether any information was stolen, or the full extent of the incidents. (Slovak Spectator)
Related: Balkan Insight, Odessa Journal, Denník N
Codegate 2026, Korea's premier international hacking defense tournament and one of the world's most prestigious arenas for white-hat hackers, was held this week in southern Seoul, where a marquee experiment co-developed by the Korea Advanced Institute of Science and Technology and the Codegate Security Forum pitted an "AI Hacker" against elite human competitors, with the AI ultimately finishing behind the top human teams.
The AI hacker surged ahead early. Starting at 18th place at 11 am on the 23rd, it jumped 11 spots to 7th by 2 pm. This was due to the AI’s rapid analysis of problems where the entire source code or executable file was provided.
The remaining problems in the latter half were different in nature. Participants had to infer hidden vulnerabilities based solely on a website or game screen. When the AI’s initial hypothesis was incorrect, it wasted time trying the same approach. In contrast, human hackers abandoned wrong hypotheses and changed their problem-solving direction based on experience and intuition.
Professor Yoon explained, “The AI excels when the entire code or executable file is given but struggles when it must infer internal vulnerabilities from limited visible information. When the AI goes astray, human intervention to correct its direction is crucial.” (Koo A-mo / The Chosun Daily)
Related: Codegate, Yonhap News, Digital Today, Korea Times
Researchers at Acronis report that an old Brazilian banking malware is still making rounds today, in ongoing attacks against Portuguese organizations.
"Lampion" — named after Japanese-style paper lamps — is a banking Trojan believed to have originated in Brazil, where banking Trojans are as culturally native as samba music. It was first discovered around the 2019 holiday season, and Portuguese organizations haven't given hackers all that much reason to modify it.
In the ongoing campaign observed by Acronis, the attackers opted to impersonate private sector organizations in Portugal, warning victims about a pending financial or administrative issue. In one phishing email template, for instance, the attackers have been impersonating an automotive documentation agency, sending victims emails with fake electronic receipts for imagined transactions they made.
The emails are decked out with all of the real iconography and information associated with the impersonated brand, and even a confidentiality notice and email signature featuring a social link. (Nate Nelson / Dark Reading)

Starting July 27, GitHub is overhauling its bug bounty program with a two-tier system that cuts rewards for public submissions while dangling much fatter payouts to a new invite-only group of researchers with proven track records.
At the same time, newcomers will find themselves capped on how many reports they can submit until they've demonstrated they can produce something worth reading.
The Microsoft-owned company says that the shake-up is a response to the flood of low-effort and AI-generated reports now accompanying many bug bounty programs. Rather than paying more people to file more reports, GitHub wants to spend more on researchers who've proved they can find the real thing. Cathering Cassell, product security engineer at GitHub. “These changes are about two things: reducing the noise so we can focus on the signal, and building a program that serious researchers find rewarding to participate in.”
For researchers sticking with the public program, a low-severity finding that previously earned between $500 and $1,000 will now bring in $250. Medium bugs top out at $2,000 instead of $5,000, high-severity flaws have been cut from as much as $20,000 to $5,000, and the maximum reward for a critical vulnerability falls from $30,000 to $10,000.
The highest rewards are now reserved for GitHub's new invite-only VIP program. There, low-severity findings are worth $1,000, medium bugs $7,500, high-severity issues $20,000, and critical vulnerabilities at least $30,000.
Entry isn't open to everyone. GitHub says invitations will be based on a proven history of valid reports, with researchers needing anything from one accepted critical vuln to seven accepted low-severity findings to qualify. (Carly Page / The Register)
Related: The GitHub Blog, Help Net Security, Hacker News
The Korean foreign ministry plans to change all diplomats' email addresses to prevent potential misuse following a data breach at an affiliated think tank, according to people close to the matter.
The personal information of all diplomats was presumed to have been leaked due to the data breach at an online education system run by the Korea National Diplomatic Academy (KNDA), in a suspected hacking that went unnoticed for 10 months until February this year.
The system had about 10,000 personal data records, most of which are believed to have been exposed in the hack.
The ministry is concerned that compromised data could be used for phishing or other sorts of cybercrimes, which could cause unforeseen damage and undermine credibility in diplomatic engagements.
The ministry was unaware that an unidentified hacker had breached the KNDA's server and it had stayed undetected since April last year, until it was alerted by a related government agency in February. (Yonhap News)
Related: The Korea Herald, The Straits Times
Robinhood CEO Vlad Tenev's X account was compromised and used to promote a fake memecoin on Robinhood Chain, the company confirmed.
That’s the visible half of an operation that, onchain records show, was set in motion hours earlier and designed to profit from the frenzy without ever pulling liquidity.
"Heads up: Our CEO Vlad Tenev's X account was compromised and posted a fake promotion for a meme coin," Robinhood's communications team said in a post on X about 41 minutes after the promotion appeared. "We're working with X to restore access and the post has been removed."
The token, called Vladhood (VLAD), drew more than $22 million in trading volume and roughly 85,000 swaps in its main Uniswap pool in the hours after the post, according to DexScreener. It was trading at about $0.0026 with a fully diluted valuation of roughly $2.6 million as of 3:55 pm ET — down about 20% over the prior hour but still up more than 90,000% from launch. The contract counted 5,266 holders and over 137,000 transfers on Robinhood Chain's block explorer, which has labeled it a scam. (The Defiant)
Related: The Cryptonomist, Crypto News, The Defiant, AMB Crypto
AegisAI, the email security company building its own LLMs to defend the inbox, announced a $36 million Series A venture capital infusion.
Battery Ventures, with participation from existing investors Accel and Foundation Capital, led the round. (Marina Temkin / TechCrunch)
Related: Runtime Wire, PR Newswire, Startup Fortune
Composable security operations startup Abstract Security said it has raised a $25 million Series A extension.
Cheyenne Ventures and AVP led the round with participation from Olive Hill Ventures, Crosslink Capital and Rally Ventures. (Duncan Riley / Silicon Angle)
Related: FinSMEs, SecurityWeek, CityBiz, Pulse 2.0
Best Thing of the Day: Don't Give Users a False Sense of Security
A teenager from New Hampshire is suing Snapchat after her account was hacked in 2021 and images stored inside her “My Eyes Only” were shared online, leading to harassment and extortion threats from strangers, according to court records.
Worst Thing of the Day: We Only Scan the Faces of Plebes for Security Purposes
Madison Square Garden owner James Dolan has insisted that the face-recognition system and array of surveillance cameras deployed at his venues is “very, very useful for security," except when it came to the wedding of Taylor Swift and Travis Kelce.
Bonus Worst Thing of the Day: Tech Giants Don't Care About No Stinkin' EU Law
EU law gives researchers unprecedented rights to scrutinize social media data, but social media giants TikTok, X, and Meta impede their efforts.
Closing Thought
