A Russian Zero-Click Attack Loots Zimbra Mailboxes & Millions of Cars Open via Bluetooth (07/23/2026)

July 23, 2026
A Russian Zero-Click Attack Loots Zimbra Mailboxes & Millions of Cars Open via Bluetooth (07/23/2026)
Key Intel / TL;DR
  • An international joint alert names Laundry Bear, a Kremlin-backed group, behind a zero-click technique against Zimbra webmail that steals 90 days of mail, the email directory, browser-saved passwords, and 2FA codes.
  • UCSD researchers found that aftermarket KARR and SWDS vehicle security systems installed by California dealers all share the same key, leaving millions of cars open to Bluetooth hijacking.
  • Oracle shipped 1,449 security patches in a single release, a volume experts tie to AI-assisted bug hunting.
  • Cisco Talos detailed msaRAT, a Rust implant used by Chaos ransomware that routes command-and-control through the victim's own headless Chrome and Edge.
  • Researchers disclosed a sandbox escape in Anthropic's Claude Cowork that could let the agent read and write files outside its Linux VM on a Mac.

The lead story today removes the step every phishing program is built around. A Kremlin-backed group spent months reading Western mailboxes through a Zimbra flaw that needed nothing from the user beyond looking at an email. Alongside it, researchers found millions of vehicles sharing a single key, and Oracle shipped patches by the thousand.

Top 5 Critical Security Alerts

1. A Russian Zero-Click Technique Loots Zimbra Mailboxes

An international joint alert from the US and partner nations names Laundry Bear, a Kremlin-backed espionage group, behind a zero-click technique against Zimbra webmail accounts worldwide (The Record, The Hacker News). The group spent months reading Western mailboxes through a then-unknown flaw in Zimbra’s webmail client, and the payload goes after the last 90 days of email, the organization’s entire email directory, the password saved in the browser, and the codes kept for two-factor authentication (Infosecurity Magazine, The Register).

Operator Note: This one needs no click, so awareness training has nothing to catch. Patch Zimbra now, then treat the mailboxes as compromised: rotate the passwords saved in those browsers, re-enroll two-factor for affected users, and pull the email directory out of reach. A stolen directory is the target list for the next campaign.

2. Millions of Cars Share One Bluetooth Key

UCSD researchers found that aftermarket KARR and SWDS vehicle security systems, installed by dealers across California, all use the same secure key, leaving millions of cars open to hijacking over Bluetooth (The Register). A single shared key across an entire product line means there is no individual compromise to contain, because recovering the key once unlocks every vehicle carrying that system.

3. Oracle Ships 1,449 Security Patches

Oracle released 1,449 security patches in one cycle, a volume that experts attribute to the arrival of AI-assisted bug hunting and a workload defenders now have to absorb (The Register). Patch volume at this scale breaks triage by hand, and the teams that cope are the ones deciding by reachability and exposure rather than reading down a list.

4. Chaos Ransomware Routes C2 Through the Victim’s Own Browser

Cisco Talos detailed msaRAT, a Rust implant used by the Chaos ransomware group ahead of its encryptor, which never opens an outbound connection of its own and instead runs command-and-control through the victim’s headless Chrome and Edge (The Hacker News). Traffic that leaves through the browser looks like the browsing every employee does all day, which is exactly why this technique defeats egress rules written around unusual processes.

Operator Note: If your detection logic assumes malware makes its own network connections, this bypasses it. Watch for headless browser processes launched outside a user session and for browser traffic originating from an unexpected parent process.

5. A Sandbox Escape in Claude Cowork

Researchers at Accomplish AI disclosed a sandbox escape in Anthropic’s Claude Cowork that makes it possible to break out of the Linux virtual machine the agent runs in and read or write files anywhere on the host Mac (The Hacker News). Agentic tools are being handed real access to real machines, and the VM boundary is the whole security model, so a hole in it turns a helpful agent into a path to everything on the laptop.

Additional Security Alerts

Threat Intelligence

  • Attackers Weaponize GitHub Actions Runners Against cPanel: A large-scale campaign turned compromised GitHub repositories into distributed attack infrastructure aimed at cPanel and WebHost Manager instances, using malicious Packagist development versions across 10 packages. The Hacker News
  • China-Nexus JadeProx Deploys a New Loader: An exposed Alibaba Cloud server revealed a China-nexus operation Group-IB tracks as JadeProx, hitting government, healthcare, and education targets across Asia and Latin America with a previously undocumented Windows loader. The Hacker News

Security Breaches & Incidents

  • Fake Claude App in Bing Ads Delivers SectopRAT: A malvertising campaign on Bing pushed a counterfeit Claude desktop installer that delivered the SectopRAT malware. BleepingComputer

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)