ctipilot.ch
Fri · 24 Jul 2026
All daily briefs ↗
Daily brief · UTC day

Friday, 24 July 2026

7 verified findings from 1 run · the settled record for this UTC day, in the classic brief order.

Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 0116-nation advisory: Russia's LAUNDRY BEAR exfiltrates government mail through a view-based Zimbra exploit, and patching alone does not evict it. A joint Cybersecurity Advisory (AA26-204A) co-sealed by security and intelligence agencies from 16 US, NATO and EU-member nations attributes a sustained email-espionage campaign against Zimbra Collaboration Suite to the Russian state actor LAUNDRY BEAR (Void Blizzard / CL-STA-1114 / TA488). Since July 2025 it has abused CVE-2025-66376 — a stored XSS in the ZCS Classic Web Client that runs on merely viewing a crafted email — to steal 90 days of mail, the Global Address List and 2FA codes, and to mint an IMAP application passcode that survives the patch and any password reset.
  2. 02A pre-auth RCE in the widely-embedded libIEC61850 substation library — energy and water OEMs, not a single product, are affected. CISA advisories ICSA-26-204-06/-07 disclose five flaws in MZ Automation's open-source libIEC61850 and lib60870 protocol libraries, embedded in IEC 61850 / IEC 60870-5-104 substation-automation and SCADA telecontrol gear. The most severe, CVE-2026-49035, is an unauthenticated heap-based buffer overflow reachable via a crafted MMS Initiate request, with RCE demonstrated where ASLR is disabled. No public exploitation is reported.
  3. 03Talos dissects a RAT that offloads all C2 into a headless browser via CDP and WebRTC — process-to-socket attribution sees only Chrome. Cisco Talos documented msaRAT, a Rust remote-access trojan used by the Chaos ransomware group whose defining trait is that the malware process itself never connects to the network — it drives a headless Chrome/Edge instance over the Chrome DevTools Protocol and tunnels C2 over a WebRTC DataChannel relayed through Cloudflare Workers and a Twilio TURN server. Endpoint tooling keyed on which process opened a socket sees only the browser.
01Active threats, incidents & disclosures3 items
NOTABLENATOB1

BravoX ransomware leaks 220 GB from a Vaud fiduciary, exposing ~15 municipalities' data and a cantonal minister's tax file

The extortion group BravoX — a Ransomware-as-a-Service operation first profiled on the RAMP underground forum in January 2026, which vets affiliates and by convention avoids CIS-based victims (SOCRadar, 2026-01-26) — breached an accounting/fiduciary firm in Yverdon-les-Bains (canton Vaud) around 30 June 2026, and on 18 July published roughly 220 GB (over 100,000 files) on its Tor leak site (Le Temps, 2026-07-22). The firm's own account describes a "connection problem" to its server that led its IT provider to isolate affected systems, revoke compromised access and restore from an external backup; no negotiation took place and no ransom was paid (Le Temps, 2026-07-22). The leaked dataset spans individuals, businesses and institutions, and includes administrative and tax records of some fifteen Nord Vaudois municipalities (Corcelles-près-Concise and Belmont-sur-Yverdon among those named) and the personal tax file of Vaud State Councillor Vassilis Venizelos and his spouse (24 heures, 2026-07-23). The firm filed a criminal complaint and notified both the cantonal data-protection commissioner and the Federal Office for Cybersecurity (BACS/OFCS) — Switzerland's mandatory critical-incident reporting channel (24 heures, 2026-07-23).

Le 18 juillet, quelque 220 Go de données y ont été publiées, soit plus de 100 000 dossiers.

Le Temps 2026-07-22

Aucune rançon n'a été versée. Une plainte pénale a été déposée et le préposé à la protection des données ainsi que l'Office fédéral de la cybersécurité ont été informés.

24 heures 2026-07-23
incident24 Jul 04:36Zmulti-sourceOpen finding ↗
NOTABLEexploitedNATOA2

US agencies expand the Iranian PLC-intrusion advisory (AA26-097A) to Schneider Electric and Siemens controllers, with new project-file tampering detection

Seven US federal agencies (CISA, FBI, NSA, EPA, the Department of Energy, US Cyber Command's Cyber National Mission Force and the Treasury) updated joint advisory AA26-097A on 22 July 2026 — first published in April 2026 on Iranian-affiliated exploitation of internet-connected, misconfigured programmable logic controllers (CISA, 2026-07-22). The update's substance is a widened scope and new detection guidance: targeting previously centred on Rockwell Automation/Allen-Bradley CompactLogix and Micro850 controllers is now confirmed to include Schneider Electric Modicon M340 and Siemens S7-1200 series controllers — both with large installed bases across European water and energy utilities (CISA News, 2026-07-22). There is no underlying software CVE: the actors scan common ICS ports (44818/2222 EtherNet/IP, 102 Siemens S7comm, 502 Modbus TCP, and 22 for Dropbear SSH on victim modems), then connect using the manufacturers' own engineering software (Rockwell Studio 5000, Schneider EcoStruxure Control Expert, Siemens TIA Portal) run from leased infrastructure with credentials obtained from weakly-protected devices, and pull down device project files (Trend Micro, 2026-07-23). The current campaign manipulates control logic directly and has produced confirmed operational disruption and financial loss: the actors modify or delete PLC logic — including reusable Add-On Instructions — and manipulate HMI/SCADA display data to disable shutdown and alarm logic, letting systems enter unsafe states without operator notification (CISA News, 2026-07-22).

The Iranian-affiliated activity outlined in this advisory has disrupted PLCs across several U.S. critical infrastructure sectors by attempting to download malicious project files and manipulate data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss for affected organizations.

CISA News 2026-07-22

Review project files running on PLCs for unauthorized changes. Use vendor-provided integrity checking tools and visually compare the running program to known good logic.

CISA / FBI / NSA / EPA / DoE / USCYBERCOM / Treasury (joint advisory AA26-097A, updated) 2026-07-22

Builds on: 2026-07-19/weekly-w29-ai-tradecraft-accelerant

threat24 Jul 04:36Zmulti-sourceOpen finding ↗
NOTABLENATOA1

German BKA dismantles Kratos, the Sneaky2FA-derived AiTM phishing-as-a-service platform behind ~15,000 monthly Microsoft 365 credential-theft campaigns

Germany's Bundeskriminalamt (BKA), with the Frankfurt cybercrime prosecutor (ZIT), US law enforcement and Indonesian authorities, announced on 20 July 2026 the takedown of Kratos — a phishing-as-a-service (PhaaS) platform that sold subscribers a turnkey adversary-in-the-middle toolkit for generating convincing Microsoft 365 authentication pages (BKA, 2026-07-20). Per BKA and Trend Micro — which had tracked Sneaky2FA's evolution into Kratos since December 2024 — the platform added browser-in-the-browser (BitB) fake login windows in November 2025 and Cloudflare Turnstile anti-bot challenges to blunt automated analysis and takedown, and ran an estimated 15,000 phishing campaigns a month across 200+ servers for roughly 1,800 subscribers (Trend Micro, 2026-07-22). Authorities seized the infrastructure and arrested the platform's developer/technical administrator in Indonesia (BKA, 2026-07-20).

Over 1,800 criminal subscribers had rented access to Kratos and used it to run an estimated 15,000 phishing campaigns a month.

Trend Micro Research 2026-07-22

bedeutender Ermittlungserfolg gegen eine der weltweit gefährlichsten Phishing-as-a-Service-Gruppierung

Bundeskriminalamt (BKA)
threat24 Jul 04:36Zmulti-sourceOpen finding ↗
NOTABLENATOA2

Mitel MiCollab AWV: unauthenticated command injection to full system compromise (CVSS 9.8, MTLVULN-1694, CVE pending)

Mitel's PSIRT advisory MISA-2026-0006 (2026-07-22, republished by CERT-FR as CERTFR-2026-AVI-0911 the next day) addresses a critical command-injection vulnerability, internally tracked as MTLVULN-1694 with a CVE requested but not yet assigned, in the Audio, Web, and Video Conferencing (AWV) component of on-premises MiCollab (Mitel, 2026-07-22). Per Mitel, insufficient parameter sanitisation in the AWV component lets an unauthenticated attacker inject and execute arbitrary OS commands — rated CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), meaning network-reachable, no credentials and no user interaction (Mitel, 2026-07-22). Affected releases run from 10.0.0.26 up to and including 10.2 SP1 FP2 (10.2.1.205) and 9.8 SP3 FP2 (9.8.3.203) and earlier; the fix ships in MiCollab 10.3.0.18, with Mitel-provided backport patches for the 10.2 SP1 FP2 and 9.8 SP3 FP2 branches (KB000128275) (CERT-FR, 2026-07-23). Neither Mitel nor CERT-FR reports exploitation at publication.

A command injection vulnerability has been identified in the Audio, Web, and Video Conferencing (AWV) component of Mitel MiCollab which, if successfully exploited, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.

Note: The above issue is referenced here by our internal tracking ID. A CVE identifier has been requested but is not yet assigned.

Mitel PSIRT (MISA-2026-0006) 2026-07-22
vulnerability24 Jul 04:36Zmulti-sourceOpen finding ↗
NOTABLECVE-2026-49035 +4NATOA2

MZ Automation libIEC61850: unauthenticated heap-overflow RCE via crafted MMS Initiate (CVE-2026-49035) plus four sibling OT-library flaws

CISA advisory ICSA-26-204-06 (2026-07-23) discloses four vulnerabilities in MZ Automation's open-source libIEC61850 (versions 1.0.0 through 1.6.1), a C library implementing the IEC 61850 MMS/GOOSE substation-automation protocols and embedded as an OEM component in energy-sector protection, control and monitoring equipment worldwide (CISA, 2026-07-23). The most severe, CVE-2026-49035 (CWE-122 heap-based buffer overflow, CVSS 3.1 8.1 / CVSS 4.0 9.2), is triggered by a crafted MMS Initiate request with no authentication and no user interaction; CISA states remote code execution has been demonstrated where ASLR is disabled, degrading to memory corruption or denial of service where it is enabled (CISA, 2026-07-23). The three companion flaws are a stack overflow via a crafted ReadRequest (CVE-2026-50039), and two null-pointer-dereference DoS conditions — one in the shared L2 GOOSE/R-GOOSE parser via a malformed TLV (CVE-2026-50103), one in the MMS Write Named Variable List handler via a WriteRequest with an empty listOfData field (CVE-2026-50032). A companion advisory, ICSA-26-204-07, covers the sibling lib60870 library (versions ≤ 2.4.0, implementing IEC 60870-5-104 SCADA telecontrol used in chemical, energy and water/wastewater sectors) with an out-of-bounds-read parser-crash DoS, CVE-2026-16002 (CISA, 2026-07-23). CISA reports no known public exploitation of any of the five.

The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

CISA (ICSA-26-204-06) 2026-07-23
vulnerability24 Jul 04:36Zsingle-source · national CERTOpen finding ↗
03Research & investigative reporting1 item
NOTABLENATOB2

msaRAT: Chaos ransomware's Rust RAT builds C2 through the Chrome DevTools Protocol so the malware process never opens a socket

Cisco Talos documented msaRAT, a Rust-based remote-access trojan deployed by the Chaos ransomware-as-a-service group, whose architecture is built to defeat the "which process opened this socket" heuristic that endpoint tooling relies on (Cisco Talos, 2026-07-23). The RAT process itself opens no external network connection. Instead it launches and controls a headless Chrome/Edge instance through the Chrome DevTools Protocol (CDP), a legitimate browser-debugging API: it connects to the browser's local CDP WebSocket (127.0.0.1 only), registers CDP bindings, and uses Runtime.evaluate to inject JavaScript that fetches STUN/TURN configuration from a Cloudflare Workers endpoint, negotiates a WebRTC PeerConnection/DataChannel (ICE plus SDP offer/answer over HTTP POST to the same Workers endpoint), and routes all subsequent C2 commands over that DataChannel through a Twilio TURN relay, double-encrypted with DTLS plus ChaCha20-Poly1305 (Cisco Talos, 2026-07-23). Because every externally-visible connection originates from the signed browser binary rather than the malware, network- and process-attribution telemetry shows only ordinary Chrome/Edge traffic to Cloudflare and Twilio infrastructure that most estates already allow.

msaRAT never touches the network directly — it controls its C2 communication channel exclusively through Chrome DevTools Protocol (CDP), a browser debugging API.

The binary contains a Cloudflare Workers endpoint, but it never makes HTTP connections to that domain itself; it offloads that work entirely to the browser.

Cisco Talos 2026-07-23
research24 Jul 04:36Zsingle-sourceOpen finding ↗
Sources: Cisco Talos
04Deep dive1 item
HIGHCVE-2025-66376exploitedNATOA1

Russian state actor LAUNDRY BEAR weaponised a Zimbra webmail zero-click (CVE-2025-66376) for mailbox exfiltration — now exposed in a 16-nation joint advisory

Background. LAUNDRY BEAR — named by the Netherlands' AIVD/MIVD in May 2025, tracked as Void Blizzard by Microsoft, CL-STA-1114 by Unit 42 and TA488 (formerly UNK_PitStop) by Proofpoint — is a Russian state-supported espionage actor that, until this campaign, relied on password spraying, adversary-in-the-middle credential phishing (a modified Evilginx) and pass-the-cookie against Microsoft Exchange and cloud mail (CISA, 2026-07-23). The 2026-07-23 joint advisory AA26-204A, co-sealed by security and intelligence agencies from sixteen US, Five Eyes and EU-member nations including ANSSI/DGSI (France), AISE/AISI (Italy), AIVD/MIVD (Netherlands) and NCSC-UK, documents its shift to a genuinely technical exploit and assesses the covert, non-extortion nature of the activity as "almost certainly" Russian-government-backed espionage (CISA, 2026-07-23).

Since at least July 2025 the actor has exploited CVE-2025-66376, a stored cross-site-scripting flaw in the Zimbra Collaboration Suite (ZCS) Classic Web Client caused by improper sanitisation of CSS @import directives in HTML email (Unit 42, 2026-07-23). A crafted message smuggles a Base64-encoded, XOR-obfuscated JavaScript payload inside an SVG element's onload attribute; the script executes inside the victim's authenticated webmail session the moment the message is rendered. CISA describes this precisely as view-based — it "only requires a user to view a malicious email within a vulnerable version of the webmail service" (CISA, 2026-07-23) — while NCSC-UK and Unit 42 call it zero-click; with preview-pane rendering the practical effect is the same, and there is no link to click or attachment to open. It was a true zero-day when first used, and Synacor did not patch it until ZCS 10.0.18 / 10.1.13 in November 2025 — yet Unit 42 confirms attackers "continue to actively target unpatched ZCS instances" today (Unit 42, 2026-07-23). This is a third, distinct ZCS Classic Web Client flaw from the two unrelated July 2026 issues this store already tracks (the no-CVE code-exec fixed in 10.1.19 and the SNMP command-injection RCE fixed in 10.1.20).

Kill chain. On render, the payload ("Ulej", Russian for beehive) pulls the session CSRF token from browser localStorage and drives a 12-stage asynchronous collection routine over the Zimbra SOAP API: it retrieves the victim's last ~90 days of mail, brute-forces the organisation's Global Address List through repeated two-character SearchGalRequest batches (roughly twenty batches of ~77 queries), harvests GetScratchCodesRequest 2FA backup codes, and — the persistence pivot — issues CreateAppSpecificPasswordRequest to mint an IMAP application passcode (observed named ZimbraWeb) that bypasses ZCS's lack of native 2FA on IMAP, then flips zimbraPrefImapEnabled to true (CISA, 2026-07-23). Because that application passcode is a legitimate credential, it survives both the November patch and any subsequent password reset — as The Hacker News put it in its analysis, patching "stops the next crafted email from running. It does not revoke what the last one left behind" (The Hacker News, 2026-07-23). Exfiltration runs over both Base32-encoded DNS A-record queries and HTTPS to a Dockerised "Flowerbed" collection stack (Catcher/Certbot/Nginx/Gardener containers, Let's Encrypt via Cloudflare DNS challenge) on short-lived VPS infrastructure reached over Mullvad VPN; CISA notes the simplistic Flowerbed codebase shows indications of AI-assisted development. Since ~November 2025 the actor has also sent lures from already-compromised victim mailboxes, defeating sender-reputation filtering (CISA, 2026-07-23). Targeting spans the Defence Industrial Base, federal and local government, education, energy, law enforcement, media and NGOs across NATO states, with Ukraine used as an earlier testbed (NCSC-UK, 2026-07-23).

Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR's latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service.

A patch for CVE-2025-66376 was released for both 10.1.13 and 10.0.18 versions of ZCS.

CISA / NSA / FBI + allied agencies from 16 nations (joint CSA AA26-204A) 2026-07-23

Threat actors continue to actively target unpatched ZCS instances using CVE-2025-66376.

Palo Alto Networks Unit 42 2026-07-23
threat24 Jul 04:36Zmulti-sourceOpen finding ↗
05Action items4 items
Verification & coverage notes1 run

2026-07-24T0409Z-intel · Claude Opus 4.8 · window 26 h · 7 entries published

Verification & coverage notes

Seven entries published, zero updates. The window was genuinely eventful, led by a marquee espionage story that all four research sub-agents surfaced independently. No critical this run and no more than one deep dive.

Marquee item — quadruple corroboration. The 16-nation joint advisory AA26-204A on the Russian actor LAUNDRY BEAR (Void Blizzard / CL-STA-1114 / TA488) exploiting a view-based Zimbra webmail flaw (CVE-2025-66376) was returned by S1, S2, S3 and S4. CVE-2025-66376 is new to the store (it was KEV-listed in March 2026 but never carried an entry) and is a distinct flaw from the two other 2026 Zimbra Classic Web Client issues already tracked (the no-CVE code-exec fixed in 10.1.19 and the SNMP command-injection RCE fixed in 10.1.20); confirmed not a duplicate. Published as the day's deep dive (apt-campaign) at high — not critical: the patch is >1 week old and this is covert espionage exfiltration rather than an hour-critical RCE wave. The entry carries the two-jobs framing (patch AND evict, because the app-specific passcode survives the patch).

  • Priority calibration: one deep dive, no criticals. The espionage campaign is high (TL;DR-worthy, active exploitation of unpatched instances) but does not clear the extreme critical bar (no in-window new weaponisation; patch long available). The remaining six are notable.

Single-source items and carve-outs:

  • Single-source (national-CERT carve-out): mz-automation-libiec61850-lib60870-ot-preauth-rce — CISA ICS-CERT is the sole authority for ICSA-26-204-06/-07 (Admiralty A). cyberav3ngers-plc-aa26-097a-schneider-siemens-expansion reaches multi-source (CISA advisory + CISA News + Trend Micro).
  • Single-source (research lab): msarat-chaos-cdp-webrtc-covert-c2 — Cisco Talos only (Admiralty B), included on detection value with the status recorded in sourcing_note.

Borderline drops (recoverable):

  • borderline-drop: Exploitarium / libssh2 CVE-2026-55200 (LevelBlue SpiderLabs) — the flagship libssh2 pre-auth OOB write is ALREADY covered store-wide (entries 2026-06-28 through 2026-07-05, including the public-PoC entry), so this is a dedup collision; also single-source and the finding carried an internal CVE-id inconsistency (2025 vs 2026-55200). Dropped.
  • borderline-drop: Saxony-Anhalt state administration incident statistics (heise, 2026-07-23) — fresh and on-lens (EU state administration) but below the Tier 2/3 technical bar: no named actor, no CVE, no TTP beyond generic phishing/DDoS categories; the holiday-staffing-timing lesson is generic. Dropped.
  • borderline-drop: Origin Energy (AU) ~5M-customer breach — no actor/TTP named, no Swiss/EU nexus; scale alone short of "genuinely global significance." (S4)
  • borderline-drop: Upbound Group 8-K (US) — US consumer-finance fraud, company-assessed not material, no transferable TTP or nexus. (S4)
  • borderline-drop: "The Gentlemen" mass leak-site postings (~10 EU claimed victims incl. Czech Philharmonic, Raben Group) — zero per-victim corroboration on any individual claim (fake-news guard requires victim disclosure or high-reliability journalism); the one CH claim in the same pull was a different, also-uncorroborated group. Actor already registered; flagged for awareness, not published. (S4)
  • borderline-drop: Jscrambler EU/US bank tracking-pixel research (darkreading) — ~41 h stale, outside the 26 h window and not a developing continuation. (S4)
  • borderline-drop: Lampion banking-trojan campaign vs Portugal (Acronis/darkreading) — a continuing campaign report, not a specific incident/victim disclosure; no distinct new TTP surfaced. (S4)

Completeness sweep: re-read all four findings sets including every borderline item; the two included borderline items (CyberAv3ngers PLC as multi-source; Mitel MiCollab on the exposed-appliance profile) were promoted with their rationale, and the drops above are all either duplicates, thin, out-of-window, or uncorroborated — no genuinely-relevant in-window item was left unpublished.

  • Coverage gaps: cert-pl (403, transport block — WebSearch substitute found nothing qualifying); chrome-releases, keycloak, sansec-research, msrc-blog (feed 0-items via jina-fallback bug — MSRC CVE checks compensated via the msrc cve API subcommand); csirt-acn-it, ccb-belgium (jina-key-exhaustion, no in-window items found via substitutes); apple-security (JS-rendered release table not extractable); sysdig (503, single-retry budget); group-ib, recordedfuture-insikt, google-tag, claroty-team82, nozomi-networks (listing pages without visible dates within time budget).
  • Essential-coverage: all essential sources attempted. cert-eu and cisa-directives were under-covered by the sub-agents and backfilled by the main agent at Phase 5 (both reachable, no in-window qualifying item). cert-pl was the only essential-tier failure (403 transport block via WebFetch, jina, and the bridge; no in-window qualifying item lost).
  • Tooling note for the operator / weekly audit: (1) refresh the jina reader API-key pool — 3 of 4 keys are balance-exhausted (HTTP 402); (2) the bridge feed subcommand silently returns 0 items when it falls through to the jina reader for a feed URL, because it does not parse the reader's markdown — recommend a raw-HTML index fallback or restricting jina to url fetches.

Watchlists: none configured in this deployment — product and supplier sweeps are no-ops (line omitted from the standard telemetry as unconfigured).