Threat Brief — 2026-07-23 — Zimbra in the Crosshairs, VPN Logs Leaked
Executive summary: Russian state-sponsored actors are actively exploiting a Zimbra Collaboration zero-click flaw combined with phishing to steal email from Western organisations, prompting a joint CISA advisory. A critical Zilliqa Ledger app bug can expose hardware-wallet private keys via flawed Schnorr-signature randomness. Meanwhile, a SplitVPN breach dumped 23.4M accounts and 58M traffic records — proving the service retained exactly what it promised it didn't — and a sandbox-escape in Anthropic's Claude Cowork lets an AI agent break out of its VM to read host files.
Top items
- Russian APT "Laundry Bear / Void Blizzard" exploits Zimbra zero-click for global webmail espionage. CISA, BleepingComputer, and Unit 42 all report that Russian state-supported actors are combining phishing with exploitation of a now-patched Zimbra Collaboration flaw to compromise email servers via JavaScript injection and credential theft. Targets span Western government and private-sector organisations. This is a distinct development from the Zimbra SNMP command-injection patch reported 2026-07-21. (src: CISA) · BleepingComputer · Unit 42)
- Critical Zilliqa Ledger app flaw lets attackers recover private keys. A randomness-generation bug in the Zilliqa hardware-wallet app's Schnorr-signature implementation for native (non-EVM) transactions means malicious inputs can lead to private-key recovery and wallet drain. Anyone using a Ledger with the Zilliqa app should treat all signed transactions as potentially compromised until patched. (src: Xakep)
- SplitVPN breach exposes 23.4M accounts and 58M traffic records. Attackers breached SplitVPN and are now selling the full dataset openly — including traffic logs the service explicitly promised not to store. This is a damning operational-security failure for a privacy-focused product and puts millions of users' browsing histories at risk. (src: SecurityLab)
- Claude Cowork sandbox escape lets AI agent break out of Linux VM and read Mac files. Researchers found that Anthropic's Claude Cowork agent can escape its VM confinement to read or write files anywhere on the host Mac. This joins a growing pattern of AI-agent sandbox escapes, though it is the first reported against Claude Cowork specifically (prior escapes targeted Cursor, Codex, and Gemini CLI, first reported 2026-07-20). (src: The Hacker News)
- China-nexus JadeProx deploys new "TriBack" loader against government and healthcare. Group-IB discovered an exposed Alibaba Cloud server revealing a China-nexus operation tracked as JadeProx, targeting organisations across Asia and Latin America with a previously undocumented loader chain. Sectors include government, healthcare, and education. (src: The Hacker News)
- Notepad++ trojanised plugin "LunchPoke" delivers stealthy persistence. Ukraine's CERT uncovered attacks distributing an archive bundling legitimate Notepad++ with a malicious plugin that establishes persistence on developer workstations. The delivery vector — a trojanised plugin masquerading as a productivity add-on — is well-suited for targeting software engineers. (src: BleepingComputer)
- Microsoft 365 outage disrupts Teams, SharePoint, Excel, and Admin Center. Users are reporting widespread access problems across multiple M365 services. This appears distinct from the Exchange Online mailbox-quarantine issue first reported 2026-07-23 and may indicate broader platform instability. (src: BleepingComputer)
Themes
Email infrastructure remains a primary espionage vector. The Zimbra campaign underscores that self-hosted collaboration suites are high-value targets — the zero-click exploitation path means even patched servers may have been compromised before updates were applied. Organisations running Zimbra should audit for indicators of compromise, not merely patch.
AI agent sandbox boundaries keep failing. Claude Cowork joins a growing list of AI coding/research tools with demonstrable sandbox escapes. As agents gain filesystem and code-execution capabilities, the assumption that VM containment is sufficient needs reassessment.
Privacy-product betrayals compound. The SplitVPN leak is the latest in a pattern of VPN and privacy services being caught retaining data they promised to discard — a reminder that no-logs claims are trust assertions, not guarantees.
