Vulnerability Watch

Forum Discussion

snarang's avatar
snarang
Product Team
4 days ago

Tenable Security Intel Brief: Russia's Zimbra zero-day ran five months undetected

Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team.

This week, Proofpoint details TA488, a Russian-aligned private contractor that quietly exploited a Zimbra zero-day for at least five months in 2025, targeting Ukrainian government and US nuclear and defense industrial base organizations.

TA488 hit US nuclear and defense targets with a Zimbra zero-day →

Brief: TA488, a Russian-aligned private contractor, exploited CVE-2025-66376, a Zimbra Collaboration Suite zero-day, for at least five months in 2025, targeting Ukrainian government and US nuclear and defense industrial base organizations.

Intel: Opening a malicious email in Zimbra's Classic UI webmail was enough to trigger the exploit. TA488 fragmented a malicious SVG tag behind fake CSS @import directives; Zimbra's sanitizer passed each fragment, and the browser reassembled them into executable JavaScript. The payload, tracked as ZimReaper, exfiltrated session security tokens, autocomplete passwords, 2FA scratch codes, the Global Address List, and 90 days of email. It registered a "ZimbraWeb" app-specific password for Internet Message Access Protocol (IMAP) access that bypassed 2FA. Zimbra patched in November 2025; no TA488 activity has been recorded since February 2026.

Why it matters: ZimReaper registered a Zimbra application credential that IMAP accepts without a second factor, one that is separate from the account password. For organizations whose mail server is the crown jewel, the half-click delivery closed the window that normally buys time. The user did nothing wrong.

GlobalProtect bypass becomes Qilin ransomware's entry point →

Brief: Arctic Wolf Labs confirmed that CVE-2026-0257, a GlobalProtect authentication bypass fixed May 13, served as the initial access vector for multiple Qilin ransomware intrusions in June 2026.

Intel: The flaw lets an unauthenticated attacker establish a valid VPN session; it is exploitable only where sign-in shortcut cookies are active alongside a specific certificate configuration. In the June intrusions, attackers dumped credentials from memory and the domain's password database, used a standard Windows admin tool to spread across the network, staged ransomware in an empty default Windows folder, then encrypted domain-wide. Tradecraft ranged from rapid encryption to full double-extortion, consistent with multiple Qilin Ransomware-as-a-Service (RaaS) affiliates. CISA flagged the CVE as exploited in ransomware attacks and Shadowserver tracks over 167,000 GlobalProtect instances exposed online.

Why it matters: Our June 3 edition noted exploitability hinged on a certificate-wiring decision, not on CVSS. Researchers observed exploitation against numerous customers starting May 17, four days after the fix shipped; confirmed ransomware intrusions followed in June. The configuration gap that decides exposure was already being industrialized before the patch cycle closed.

HOLLOWGRAPH turns Microsoft 365 calendars into an espionage dead-drop →

Brief: Group-IB identified HOLLOWGRAPH, a malware implant using a compromised Microsoft 365 mailbox calendar as a two-way command channel, hiding operator tasking and stolen files inside events dated May 13, 2050.

Intel: HOLLOWGRAPH runs two commands through the Microsoft Graph API, the cloud interface for Microsoft 365: 'get' pulls instructions from a planted calendar attachment; 'send' uploads stolen files into a new far-future event. No flaw is exploited; the malware uses a compromised account and stolen login credentials, leaving no patch. Group-IB tied the implant to Cavern Manticore with high confidence but could not attribute the campaign to any known actor. The Iranian-nexus link comes from a separate Check Point report covered in our July 15 edition. Group-IB counted 12 infected systems between June 3 and July 9, with a focus on Israeli entities.

Why it matters: Detection built around flagging traffic to attacker-owned destinations has nothing to match when the command channel is a legitimate Microsoft 365 calendar. The 2050 date parks dead-drop events in a corner of the mailbox no one monitors, and two commands run a complete espionage loop.

Oracle's CPU and a kernel flood put CVE volume on trial →

Brief: Oracle's July 2026 Critical Patch Update, its quarterly patch bundle, addresses 1,235 unique CVEs in 1,449 patches across 32 product families, the largest CPU release in our analysis.

Intel: Context: the January 2026 CPU covered 158 CVEs; April covered 241. That same week, 432 CVEs landed from the Linux kernel team, which issues its own CVEs, in a 31-hour window ending July 20. Jan Schaumann flagged the volume on OSS-SEC; Greg Kroah-Hartman, who oversees the kernel CVE program, explained it: "These were all pending for weeks," the result of "a perfect storm of 6 week straight of conferences and vacations." Kroah-Hartman added that "the number of llm-found issues is only on the rise right now."

Why it matters: When one quarterly update carries 1,235 CVEs and the kernel publishes 432 in a weekend, a CVE stops working as a signal to act and becomes a unit of accounting. NVD has logged 45,207 CVEs this year, on pace to roughly double 2025's total; Bloomberg found no rise in exploitation.

Stat of the week: $124 million

Recorded financial exposure from wrench attacks (incidents where criminals use violence or threats to steal cryptocurrency) in 1H 2026, according to CertiK, which counted 52 verified incidents, up from 39 incidents and $10.5 million a year earlier.

Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.

No RepliesBe the first to reply