Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Russian state-sponsored threat group Laundry Bear (also known as APT28 or Fancy Bear) exploited a Zimbra zero-day vulnerability in targeted email campaigns against US government entities. The attack used half-click exploits — emails that require minimal user interaction such as viewing the message in a preview pane — to trigger the vulnerability and compromise mail servers without requiring the victim to open attachments or click links.
This article reports on a Russian state-sponsored hacking group, dubbed Laundry Bear, that is exploiting a Zimbra zero-day vulnerability to target organizations in the US and Ukraine. The group uses a unique 'half-click' phishing technique, where merely opening or previewing an email can trigger the exploit.
This article is a Threat Source newsletter that reflects on the current state of AI in cybersecurity, describing a shift from a 'pre-Mythos' to a 'post-Mythos' era. It highlights the rapid advancement of AI models, including open-weight options like GLM-5.2, which are closing the capability gap with closed models.
Cisco Talos has identified a new Rust-based remote access trojan (RAT) called "msaRAT," developed by the Chaos ransomware group. This malware leverages the Tokio asynchronous runtime to establish a covert command-and-control (C2) channel by exploiting the Chrome DevTools Protocol (CDP) in Chrome or Edge browsers.
Lately I've found myself thinking a lot...
This article is a Threat Source newsletter that reflects on the current state of AI in cybersecurity, describing a shift from a 'pre-Mythos' to a 'post-Mythos' era. It highlights the rapid advancement of AI models, including open-weight options like GLM-5.2, which are closing the capability gap with closed models.