Daily Briefing

Cybersecurity & Geopolitics Briefing — Friday, July 24, 2026

Geopolitical cyber intelligence in 5 minutes
Friday, July 24, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Friday, July 24, 2026, and 1 disclosed vulnerability (CVE-2026-16870). Each entry links to the original reporting.

Share this digest:

Russia's Laundry Bear Exploits Zimbra Zero-Click Flaw to Steal Email (1 minute read)

CISA warns Russia's Laundry Bear (Void Blizzard) is chaining phishing with a now-patched Zimbra vulnerability to exfiltrate email from targeted organizations. The zero-click attack vector lowers the bar for mass credential and inbox harvesting across Western targets.

BleepingComputer · 16h ago · Read full article →

Russia's Laundry Bear Reads Western Mailboxes via Zimbra Zero-Day for Months (1 minute read)

A Russian state espionage group exploited an unknown Zimbra webmail flaw to silently steal 90 days of email, directory data, saved passwords, and 2FA recovery codes โ€” triggered by simply opening a message.

The Hacker News · 14h ago · Read full article →

Laundry Bear's Half-Click Zimbra Phishing Hits US and Ukraine Targets (1 minute read)

Russia's Laundry Bear sends phishing emails that execute on open or preview, requiring no user interaction beyond viewing the message. US and Ukrainian organizations are confirmed targets, signaling active intelligence collection against both NATO-adjacent and frontline-state networks.

Dark Reading · 12h ago · Read full article →

Laundry Bear Exploited Zimbra Zero-Day Five Months Before November 2025 Patch (1 minute read)

Russia's Laundry Bear ran undetected inside Zimbra environments for five months before a November 2025 patch, and continues exploiting unpatched systems. Prolonged dwell time against Western governments signals sustained collection, not opportunistic access.

CyberScoop · 15h ago · Read full article →

China-Nexus JadeProx Deploys TriBack Loader Against Government and Healthcare Targets (1 minute read)

Group-IB exposed a China-linked operation, JadeProx, via an unsecured Alibaba Cloud Singapore server hosting a previously undocumented Windows loader, TriBack, used against government, healthcare, and education sectors across Asia and Latin America.

The Hacker News · 21h ago · Read full article →

Laundry Bear's Zero-Click Phishing Hits Zimbra Accounts Globally (1 minute read)

A joint international alert names Russia-linked Laundry Bear for exploiting a zero-click phishing technique against Zimbra webmail targets worldwide. The campaign signals sustained Kremlin interest in covert access to government and enterprise communications infrastructure.

The Record · 16h ago · Read full article →

Russia-Linked Laundry Bear Infects Zimbra Users on Email Open (1 minute read)

A year-long Russian campaign targeting Zimbra webmail triggers compromise the moment a victim views a phishing email, requiring zero clicks. The zero-interaction vector removes user-behavior mitigations as a meaningful defensive layer.

The Register Security · 16h ago · Read full article →

Trump Threatens to Strike Iranian Infrastructure Over Strait of Hormuz Attacks (2 minute read)

President Trump publicly threatened to destroy Iranian bridges or power plants, including in Tehran, for each ship attacked in the Strait of Hormuz. The explicit infrastructure targeting threat raises escalation stakes in a conflict corridor handling roughly 20% of global oil transit.

Just Security · 21h ago · Read full article →

Houthi Attacks on Saudi Shipping Threaten Red Sea as New Crisis Front (1 minute read)

Houthi strikes on Saudi commercial vessels risk internationalizing the Iran conflict by opening a second maritime chokepoint alongside the Strait of Hormuz. A sustained Red Sea interdiction campaign would pressure global energy and container shipping simultaneously.

Foreign Policy · 11h ago · Read full article →

Iran-Linked Actors Probe US Critical Infrastructure Beyond Rockwell Controllers (1 minute read)

CISA expanded its alert as Iran-linked intrusion crews target internet-exposed industrial control devices across multiple vendor platforms, not just Rockwell Automation systems. Broadening target scope signals a reconnaissance campaign against US critical infrastructure ahead of potential escalation.

The Register Security · 18h ago · Read full article →

Pew Survey Shows Global Opinion Favors China Over U.S., With Caveats (1 minute read)

A new Pew Research survey records higher global favorability for China than the United States, though deeper analysis reveals the shift reflects U.S. decline more than Chinese gains. The perception gap still matters for diplomatic alignment and multilateral institution influence contests.

Foreign Policy · 19h ago · Read full article →

European NATO Members Push Autonomous Defense Pillar Amid US Uncertainty (3 minute read)

Two years after arguing NATO needed structural reform to build a European defense pillar, analyst Max Bergmann reassesses progress as Secretary General Rutte openly pressures European parliaments to shoulder greater security burden.

War on the Rocks · 13h ago · Read full article →

China Frames Planetary Defense Program Around National Security and Soft Power (1 minute read)

China is investing in planetary defense as both a legitimacy-building exercise internationally and a dual-use national security capability. The same political constraints limiting transparency also cap China's actual contribution to global asteroid-threat coordination.

The Diplomat · 19h ago · Read full article →

Iran Outmaneuvers Washington, Reshaping U.S. Middle East Options (1 minute read)

Iran has consolidated strategic leverage over the U.S. through a combination of proxy warfare, nuclear brinkmanship, and Hormuz denial threats. Washington's remaining off-ramps are narrowing as each escalation cycle strengthens Tehran's negotiating position.

Foreign Policy · 11h ago · Read full article →

China Closes AI Gap With U.S. as Beijing Accelerates Development (1 minute read)

New assessments indicate China is narrowing the capability gap with the United States in frontier AI development. Closing the gap shifts the strategic calculus on export controls, compute restrictions, and technology alliance cohesion.

Foreign Policy · 13h ago · Read full article →

U.S. Analysts Urge Iran Payoff to Reopen Hormuz, Freeze Nuclear Program (1 minute read)

Analysts argue the only viable U.S. exit from the Iran conflict is a financial-for-freeze deal trading sanctions relief for Hormuz access and nuclear suspension. The proposal concedes strategic initiative to Tehran and sets a precedent for coercive nuclear bargaining.

Foreign Policy · 16h ago · Read full article →

Chaos Gang's msaRAT Tunnels C2 Traffic Through Chrome and Edge Browsers (1 minute read)

The Chaos ransomware gang deployed a new backdoor, msaRAT, that routes command-and-control traffic through Chrome or Edge browser processes to blend into normal web traffic. Browser-masquerading C2 complicates detection by endpoint and network tools that whitelist browser activity.

BleepingComputer · 23h ago · Read full article →

Chaos Ransomware's msaRAT Tunnels C2 Traffic Through Victim Browsers (1 minute read)

Chaos ransomware group deploys msaRAT, which hijacks the victim's browser to route C2 traffic via WebRTC over TURN, masking attacker IP. The technique complicates network-level detection and sets a replicable template for C2 obfuscation without custom infrastructure.

Cisco Talos · 23h ago · Read full article →

AI-Generated Exploits Outpace Patch Cycles, Forcing Strategy Rethink (1 minute read)

Working exploits can now be generated from vulnerability descriptions in under 20 hours, rendering traditional patch-prioritization models structurally obsolete. Security teams must shift from patch velocity to exposure reduction and resilience architecture.

SecurityWeek · 18h ago · Read full article →

CVE-2026-16870: Snowflake libsnowflakeclient RCE and Credential Theft Flaw (4 minute read)

CVE-2026-16870 exposes Snowflake libsnowflakeclient versions before 2.9.2 to remote code execution via a stack-based buffer overflow in the file download path and credential exfiltration through crafted encryption metadata.

CVE Feed (High Severity) · 3h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now