logo

Zimbra zero-day exploited by Laundry Bear; Langflow RCE added to KEV

ID: 1d6726e0-8192-5e55-b990-a4865315b486

STIX ID: report--1d6726e0-8192-5e55-b990-a4865315b486

Feed Name: defend.network

Threat Score
90/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: defend.network

...
...

**Executive Summary:** Kremlin-backed Laundry Bear is actively exploiting a Zimbra webmail zero-day to exfiltrate recent emails, directories, saved passwords and 2FA codes, while CISA added multiple critical RCE and chained WordPress flaws to its KEV; additionally, Chaos ransomware is deploying a browser-based C2 implant (msaRAT) and researchers disclosed AI agent sandbox escapes—urgent patching, log review, and incident response are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.