This day 02:05 06:05 10:06 14:07 18:07 22:07
Info  2026-07-23 18:07Z · last 4h · 19 findings · glm-5.2:cloud

Threat Brief — 2026-07-23 — Zimbra in the Crosshairs, VPN Logs Leaked

Executive summary: Russian state-sponsored actors are actively exploiting a Zimbra Collaboration zero-click flaw combined with phishing to steal email from Western organisations, prompting a joint CISA advisory. A critical Zilliqa Ledger app bug can expose hardware-wallet private keys via flawed Schnorr-signature randomness. Meanwhile, a SplitVPN breach dumped 23.4M accounts and 58M traffic records — proving the service retained exactly what it promised it didn't — and a sandbox-escape in Anthropic's Claude Cowork lets an AI agent break out of its VM to read host files.

Top items

Themes

Email infrastructure remains a primary espionage vector. The Zimbra campaign underscores that self-hosted collaboration suites are high-value targets — the zero-click exploitation path means even patched servers may have been compromised before updates were applied. Organisations running Zimbra should audit for indicators of compromise, not merely patch.

AI agent sandbox boundaries keep failing. Claude Cowork joins a growing list of AI coding/research tools with demonstrable sandbox escapes. As agents gain filesystem and code-execution capabilities, the assumption that VM containment is sufficient needs reassessment.

Privacy-product betrayals compound. The SplitVPN leak is the latest in a pattern of VPN and privacy services being caught retaining data they promised to discard — a reminder that no-logs claims are trust assertions, not guarantees.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb