🚨 ACTIVE EXPLOITATION
- Russian Hackers Exploit Zimbra Zero-Day in US and Ukraine Attacks — Dark Reading
Russian state-sponsored hackers exploited a zero-day vulnerability in Zimbra Collaboration Suite targeting organizations in the US and Ukraine.- Targets include US and Ukraine organizations using Zimbra email servers
- Vulnerability exploited is a zero-day in Zimbra Collaboration Suite
- Attack delivered via 'half-click' phishing emails requiring only message preview or open
- Threat actor identified as state-sponsored group 'Laundry Bear'
🕵️ RESEARCH & DEEP DIVES
- New Dolphin X malware uses AI to rank and prioritize high-value victims — BleepingComputer
Dolphin X malware employs AI to profile infected users and prioritize them for targeted credential theft and exploitation.- Targets infected users across more than 300 applications including browsers, crypto wallets, and password managers
- Features an AI Profiler that analyzes app usage, risk scores, and installed software to assign risk ratings
- AI-generated daily summaries help attackers prioritize high-value victims for credential theft and further exploitation
- Credential-stealing capabilities include harvesting .env files, SSH keys, cloud tokens, and browser login data
- Analysis based on operator panel and network traffic; live malware sample not executed or fully confirmed
🔓 CVEs & KEV
- 20 CVEs reported, with the worst scoring 10.0 on CVSS.