Info
2026-08-20 10:08Z · last 4h · 24 findings
· glm-5.2:cloud
Threat Brief — 2026-08-20 — Zimbra RCE Goes Live, C2 Hides in GitHub
Executive summary. A critical Zimbra Collaboration Suite RCE is now being actively exploited in the wild per CERT Polska — patch immediately if ZCS is in your environment. Separately, a new C2Looper backdoor variant uses GitHub as its command channel, eliminating the need for a dedicated C2 server and making detection harder. Chinese threat actors are targeting Myanmar diplomatic personnel with malicious "photo" lures that deploy hidden backdoors.
Top items
- Critical Zimbra Collaboration Suite RCE now actively exploited. CERT Polska warns attackers have begun exploiting a critical vulnerability in ZCS in real attacks. No CVE ID provided in the source, but the active-exploitation status makes this the highest-priority patching item today if Zimbra is deployed in your infrastructure. (src: BleepingComputer)
- Chinese hackers target Myanmar diplomats with backdoor-laden "photos." Opening what appears to be a ceremonial invitation image triggers a hidden backdoor on the victim's machine. This is a social-engineering-heavy spear-phishing pattern aimed at diplomatic targets — relevant if your org engages with Southeast Asian government partners. (src: SecurityLab)
- C2Looper backdoor uses GitHub as command-and-control, no server required. A new version of the C2Looper backdoor pulls instructions from GitHub, removing the need for attacker-controlled infrastructure and making C2 traffic blend into legitimate GitHub API calls. Detection will require monitoring for unusual GitHub API activity from endpoint processes. (src: SecurityLab)
- ClarityCheck exposed photos of 9 million faces via a single leaked link in page source. A biometric-focused platform that promised privacy inadvertently exposed its entire face-image dataset through an exposed link in its own page source code. Highlights the persistent risk of client-side secrets and underscores why biometric data repositories need aggressive access controls. (src: SecurityLab)
- Researchers revive "dead" bank cards at checkout using two cheap phones in 400ms. Discarded/expired cards can be made to complete live transactions through a relay attack using two inexpensive phones, defeating assumptions that disposed cards are inert. Relevant for any organization issuing physical payment cards or handling card lifecycle management. (src: SecurityLab)
- EncroChat hack method reconstructed: police used a public exploit from GitHub. Experts have now reconstructed how law enforcement compromised EncroChat — by leveraging a publicly available exploit hosted on GitHub. This confirms that police operations can and do rely on open-source exploit code, and reinforces that "secure" communications platforms should not assume obscurity of their underlying vulnerabilities. (src: SecurityLab)
- Court to decide fate of alleged LockerGoga ransomware developer. A cybersecurity consultant is facing trial as the suspected author of the LockerGoga ransomware, with a crypto wallet holding 1.8 million Swiss francs complicating the "just a consultant" defense. This case could set precedent for how ransomware authorship is prosecuted in Europe. (src: SecurityLab)
Themes
- Legitimate platforms as attack infrastructure. Both C2Looper (GitHub) and the EncroChat compromise (public GitHub exploit) illustrate a growing pattern of adversaries abusing legitimate developer platforms — either for C2 channels or as a source of ready-made exploit code. Blocking or monitoring GitHub API traffic from non-developer endpoints is increasingly necessary.
- "Photo" as the new weaponized file format. The Myanmar diplomat attack and the Meta iPhone image-crash vulnerability (previously reported 2026-08-20) both demonstrate that image files remain a high-yield delivery vector across both desktop and mobile platforms.
