Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

Zimbra zero-click, and a 15-nation reply

3 min read
18:20UTC

A 15-nation coalition named Russian actor LAUNDRY BEAR behind a zero-click Zimbra exploit, while two Scattered Spider hackers drew record UK sentences for the TfL attack. CISA's catalogue ran a month behind private detection on a Fortinet flaw, and River Financial answered the materiality question with 'not yet determined' for a fourth time. The machinery of defence, not a single breach, is the story of the fortnight.

Key takeaway

The defence machinery is scaling coalitions and prosecutions faster than it can patch its own catalogue.

This briefing mapped
Infrastructure
Legal
Regulatory
Economic

CISA, the NSA and the FBI named Russian actor LAUNDRY BEAR behind a zero-click Zimbra flaw that reads 90 days of mail on a single preview, in an advisory fifteen agencies co-sealed.

Sources profile:This story draws on neutral-leaning sources

The Cybersecurity and Infrastructure Security Agency (CISA), the NSA and FBI led 15 nations in naming Russian group LAUNDRY BEAR on 23 July. It exploited a zero-click flaw in Zimbra webmail to read victims' email for up to 90 days without any click.

A patch existed eight months before the warning. Many self-hosted Zimbra servers never applied it, showing how slowly patches move once software leaves the vendor's direct control. 

Sources:CISA

Owen Flowers, 18, and Thalha Jubair, 20, drew five years six months each for the 2024 Transport for London hack that disabled 148 systems and cost £29 million.

Sources profile:This story draws on neutral-leaning sources

Woolwich Crown Court jailed Owen Flowers and Thalha Jubair for five years and six months each on 16 July. The pair were convicted over the September 2024 Scattered Spider attack that disabled 148 Transport for London systems and exposed data on 10 million passengers.

The National Crime Agency called it Britain's largest-ever cybercrime prosecution. Flowers was arrested while hacking two US healthcare providers, showing the same crew kept operating after the TfL attack. 

City of London Police Commander Ollie Shaw used the TfL sentencing to press for Cyber Crime Risk Orders, restrictions on a hacker's technology access that UK law does not yet provide.

Sources profile:This story draws on neutral-leaning sources

City of London Police Commander Ollie Shaw pressed for a new court power after the 16 July TfL sentencing. He called it Cyber Crime Risk Orders, a 'digital prison' model that does not yet exist in UK statute.

The proposed orders would let judges restrict a convicted hacker's device and internet access after release, similar to restriction orders already used for other offence categories. 

CrowdSec flagged live exploitation of Fortinet's FortiSandbox on 17 June; CISA's Known Exploited Vulnerabilities catalogue did not list the flaw until 16 July, a month later.

Sources profile:This story draws on neutral-leaning sources

CrowdSec spotted hackers actively exploiting a flaw in Fortinet's FortiSandbox appliance on 17 June. The Cybersecurity and Infrastructure Security Agency (CISA) did not add that flaw, CVE-2026-39808, to its official actively-exploited list until 16 July, a full month later.

That list matters because federal patch deadlines only start once a flaw is added to it. The month-long gap left no such deadline in place while attackers were already exploiting the appliance. 

Sources:CrowdSec

CISA listed a second Langflow flaw, CVE-2026-0770, on 21 July, two months after Iran-nexus MuddyWater exploited the framework's first catalogued bug.

Sources profile:This story draws on neutral-leaning sources

CISA added a second Langflow vulnerability, CVE-2026-0770, to its actively-exploited list on 21 July, giving federal agencies until 24 July to patch. That is Langflow's second listing in two months, after its first entry in May.

Langflow builds AI agent pipelines and often stores the passwords for every service it connects to. Two exploited flaws in two months make it one of the fastest-repeating targets on CISA's list this year. 

Sources:CISA

CISA added two Microsoft SharePoint deserialization flaws to its exploited-vulnerabilities catalogue on 16 and 22 July, days after a 14 July hardening advisory.

Sources profile:This story draws on neutral-leaning sources

CISA added two more Microsoft SharePoint security flaws, CVE-2026-58644 and CVE-2026-50522, to its actively-exploited list on 16 and 22 July. CVE-2026-58644 and CVE-2026-50522 are both deserialisation bugs, letting attackers run malicious code on vulnerable servers.

It is SharePoint's third such listing in three weeks, following an earlier flaw CISA catalogued on 1 July. Organisations running their own SharePoint servers face a third urgent patch cycle in under a month. 

Sources:CISA

CISA gave Oracle E-Business Suite a three-day federal patch deadline on 15 July for a privilege-management flaw on a platform with a Clop extortion history.

Sources profile:This story draws on neutral-leaning sources

CISA gave Oracle E-Business Suite a three-day patch deadline on 15 July for CVE-2026-46817, a privilege-management flaw. It is one of the shortest windows CISA sets under its risk-tiered rules.

Oracle's E-Business Suite software runs finance and HR systems for large companies. The extortion crew Clop has a history of exploiting similar enterprise software, most famously the 2023 MOVEit campaign. No attacker has yet been tied to this specific flaw. 

Sources:CISA

River Financial's fourth filing on 17 July again recorded the ransomware breach's materiality and personal-data scope as undetermined, even as a fourth class action landed.

Sources profile:This story draws on neutral-leaning sources

River Financial Corporation filed its fourth disclosure with the Securities and Exchange Commission (SEC) on 17 July, about a June ransomware attack. It again said it cannot yet determine whether the incident is material or how much customer data was exposed.

More than a month after the intrusion, the bank still has no scoped answer. Four separate class-action lawsuits have already been filed against it over the breach. 

Sources:SEC EDGAR
Closing comments

Sideways. The mechanism that would tip this up is the FY27 appropriations outcome: if Congress confirms the $707m CISA cut and 860-position reduction, the FortiSandbox-style listing lag becomes structural rather than an isolated incident, and allied agencies co-signing advisories like AA26-204A would be absorbing more of the attribution workload CISA currently anchors. The mechanism that would tip it down is a Cyber Crime Risk Orders provision landing in a forthcoming Criminal Justice Bill, converting Commander Shaw's post-sentencing advocacy into an enforceable post-release restriction the courts currently lack.

Different Perspectives
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.