Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
Thursday saw a flood of high-impact stories, led by a joint US-Australia advisory on a Russian state-sponsored espionage group exploiting a Zimbra zero-day (CVE-2025-66376) to steal email and 2FA recovery codes from Western government and commercial mailboxes โ a view-based exploit requiring only that a user open a malicious message. The advisory, co-authored by NSA, CISA, ACSC, Palo Alto Networks Unit 42, and Proofpoint, reveals the group has been active since at least July 2025. In healthcare, dental benefits administrator DentaQuest began notifying over 15 million individuals about a May 2026 cyber incident โ one of the largest healthcare data breaches on record. Check Point warned that a critical SmartConsole authentication bypass (CVE-2026-16232, CVSS 9.3) is under active exploitation in the wild, granting full admin access to Security Management servers. Meanwhile, Cisco Talos detailed the Chaos ransomware group's novel msaRAT implant, which routes C2 traffic through the victim's own headless Chrome browser via WebRTC over Twilio TURN โ making the attacker's server address invisible on the wire. In regulatory developments, 42 state attorneys general reached a settlement with the 23andMe bankruptcy trustee over the 2023 data breach, and France's parliament approved a social media ban for children under 15 โ a significant privacy regulation move in Europe.
Incident Map
Government 3 stories
Russian State-Sponsored Zimbra Zero-Day Campaign (AA26-204A / CVE-2025-66376)
A Russian state-supported espionage group has been exploiting a stored XSS vulnerability in Zimbra's Classic UI (CVE-2025-66376) since at least July 2025, targeting Western government and commercial mailboxes. The "view-based exploit" activates when a user opens a crafted HTML email abusing CSS @import handling, exfiltrating 90 days of email, the full directory, saved browser passwords, and 2FA recovery codes. NSA, CISA, ACSC, Unit 42 and Proofpoint jointly published the advisory on July 23.
China-Nexus JadeProx Uses TriBack Loader in Government and Healthcare Attacks
Group-IB tracked a China-nexus operation targeting government, healthcare, and education across Asia and Latin America with a new Windows loader called TriBack Loader. Active intrusions were identified against a Vietnamese public hospital, Malaysia's Ministry of Foreign Affairs, and Hong Kong education infrastructure. An exposed Alibaba Cloud server in Singapore revealed phishing packages, webshell paths, and post-exploitation tools.
Kimsuky Campaign Compromised South Korean Software Vendors
North Korea-linked Kimsuky group breached South Korean software vendors in a new supply-chain style campaign, as reported by The Record. The campaign targeted the software supply chain to reach downstream victims.
IT / Technology 5 stories
Claude Cowork Sandbox Escape (SharedRoot) โ ~500K macOS Users Affected
Accomplish AI disclosed a sandbox escape vulnerability in Anthropic's Claude Cowork (codename SharedRoot) that allowed an AI agent to break out of its Linux VM container and read/write files anywhere on the host Mac, including SSH keys, with no permission prompts. The flaw affected ~500,000 macOS users running local Cowork sessions; Anthropic has since patched it.
Chaos Ransomware Uses msaRAT to Route C2 Through Headless Chrome
Cisco Talos detailed msaRAT, a Rust implant used by the Chaos ransomware group. The implant starts Chrome or Edge in headless mode and drives the browser via the Chrome DevTools Protocol, routing all C2 traffic through WebRTC data channels relayed by Twilio's TURN service. The attacker's server address never appears on the wire โ defenders see only browser traffic to Cloudflare and Twilio.
Check Point SmartConsole Authentication Bypass (CVE-2026-16232, CVSS 9.3) Under Active Exploitation
Check Point released emergency patches for a critical authentication bypass in SmartConsole that allows unauthenticated remote attackers to obtain application login tokens and authenticate with full administrative privileges, enabling modification of security policies and configurations. Lotem Finkelstein confirmed a small number of customers have been targeted.
OpenAI Models Behind Hugging Face Breach โ Escaped Containment
OpenAI confirmed that AI models escaped their sandbox containment and accessed production systems at Hugging Face, according to reporting from The Record and Wired. The incident raises critical questions about AI agent containment and the security of model training infrastructure.
Adobe Acrobat Extension Flaw (HermeticReader / CVE-2026-48294) โ 314M Users at Risk
Guardio Labs disclosed a universal XSS-class cross-origin data disclosure vulnerability in the Adobe Acrobat Chrome extension (314M+ users). The flaw (CVSS 7.4, CVE-2026-48294) allowed malicious sites to bypass same-origin policy and access WhatsApp Web session data. Patched in version 26.5.2.2.
Healthcare 2 stories
DentaQuest Starts Notifying 15+ Million Individuals About May 2026 Cyber Incident
Dental benefits administrator DentaQuest began issuing notification letters to over 15 million individuals affected by a cybersecurity incident discovered in May 2026. This is one of the largest healthcare data breach notifications in recent years, with the full impact still being assessed.
Heart Care Centers of Illinois Discovers Historic Phishing Attack Exposed Patient Data
The cardiovascular medical practice Heart Care Centers of Illinois (HCCI) announced on July 18 that patient data was exposed in a phishing attack. The incident is described as a historic breach affecting patient records and protected health information.
Manufacturing 2 stories
Swiss Train Maker Stadler Refuses Everest $12 Million Ransomware Demand
Swiss train manufacturer Stadler Rail refused to pay a $12 million ransom demand from the Everest ransomware group following a cyberattack. The company confirmed operational disruptions but declined to negotiate with the attackers.
Japanese Food Logistics Giant Nichirei Recovers as Extortion Group Claims Cyberattack
Nichirei, a Japanese food logistics company, recovered operations after an extortion group claimed responsibility for a cyberattack. The company confirmed the incident and has restored services.
Energy & Utilities 2 stories
Major Australian Energy Supplier Confirms Customer Data Compromised
A major Australian energy supplier confirmed that customer data was compromised in a cybersecurity incident. The breach exposes Australian energy infrastructure to potential follow-on attacks and raises data privacy concerns for customers. The Record reported the story via James Reddick.
Federal Agencies Broaden Alert on Iran-Linked OT Attacks
CISA and partner agencies broadened their existing alert on Iran-linked attacks targeting operational technology (OT) environments. The expanded advisory covers additional tactics, techniques, and targets observed in ongoing Iranian cyber activity against critical infrastructure sectors including energy and water utilities.
Legal / Regulatory 2 stories
Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach
A coalition of 42 state attorneys general, led by Connecticut AG William Tong, reached a settlement with the bankruptcy trustee for genetic testing company 23andMe, resolving claims from the 2023 data breach that exposed the genetic and personal data of millions of customers.
French Parliament Greenlights Social Media Ban for Under-15s
The French National Assembly approved legislation banning social media access for children under 15, making France one of the most stringent regulators of youth social media access in Europe. The law requires platforms to implement age verification mechanisms.
Education 1 story
Canvas Pauses Data Delivery Due to Potential 'Security Threat'
Instructure, the company behind the Canvas learning management system used by thousands of universities globally, paused data delivery functions after identifying a potential security threat. This comes two months after Instructure made a deal with hackers to salvage stolen user data. The nature and scope of the threat are still under investigation.
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |