Novel APT Operations, In-the-Wild Exploits and New 0-Days, High-Profile Compromises
APT: new operations conducted across Eurasia and the Middle East
Since at least July 2025, the Russian state-sponsored group Void Blizzard (also known as Laundry Bear, CL-STA-1114, and TA488) has targeted Western government and commercial organizations using Zimbra Collaboration Suite (ZCS) by exploiting CVE-2025-66376, a Stored Cross-Site Scripting (XSS) vulnerability in the Classic UI that was used as a 0-day and patched in November 2025. The exploit, dubbed Ulej and also observed as ZimReaper, is a half-click exploit that enables the automatic execution of JavaScript code when a malicious email is viewed, without requiring the victim to open attachments or click links. Targeted sectors include the defense industrial base (DIB), government (federal and local), education, energy, law enforcement, media, non-governmental organizations, technology, transportation, and finance. Initial targeting focused on Ukraine before expanding to NATO member states, as well as organizations across the Commonwealth of Independent States (CIS) and Africa. Also linked to Moscow, TA458 has continued Operation RoundPress (previously associated with Sofacy), aimed at deploying SpyPress by targeting webmail platforms through half-click XSS exploits. The campaign has primarily affected Ukrainian government entities and military and government installations across Eastern Europe, while also occasionally targeting companies operating in the chemical, telecommunications, and technology sectors. The activity has been associated with the exploitation of both 0-day and n-day vulnerabilities affecting SOGo, Kerio, Zimbra, mDaemon, and Roundcube, including CVE-2026-8496, CVE-2025-27915, CVE-2025-3929, CVE-2023-43770, and CVE-2024-42009. In Asia, security researchers tracked an adversary believed to be linked to Beijing that employed the open-source AI agent Hermes in an unsupervised YOLO mode during an intrusion into the network of Thailand’s Ministry of Finance. The operation involved the deployment of a previously undocumented cross-platform Go implant named Hades. Data recovered from an exposed server in Hong Kong revealed the presence of exploits, web shells, HTTP tunnels, hardcoded credentials, compiled payloads, and agent logs. The AI agent was used to enumerate hosts, analyze file systems, assess privilege escalation opportunities, and identify internal documents and logs.
In addition, security researchers linked, with medium confidence, the compromises of the npm packages typo-crypto, debug, chalk, and axios to the North Korean state-sponsored Lazarus Group. The attribution is based on shared command-and-control (C2) infrastructure and common tactics, techniques, and procedures (TTPs). The analysis confirms that the Pyongyang-backed APT continues to refine its open-source supply chain compromise capabilities through long-term campaigns of increasing operational sophistication. Finally, in July 2026, researchers identified a campaign attributed to an adversary linked to East Asia targeting government entities in the Middle East. The operation relied on a multi-stage attack chain that deployed the previously undocumented malware families TELESHIM, MIXEDKEY, and BINDCLOAK.
Vulnerabilities: multiple ITW flaws exploited and new 0-days patched
Throughout June 2026, several intrusions were identified in which CVE-2026-0257 (CVSS 7.8), an Authentication Bypass vulnerability affecting the Palo Alto Networks PAN-OS GlobalProtect portal and gateway, was exploited as the initial access vector for the deployment of Qilin ransomware. In some cases, the adversaries also exfiltrated data to cloud storage services before deploying the ransomware. Following evidence of active exploitation, on July 27, 2026, CISA added Arista Networks CVE-2026-16812 and Fortinet CVE-2025-68686 to its Known Exploited Vulnerabilities (KEV) Catalog. The former is an OS Command Injection vulnerability that could allow a remote attacker to access internal functionalities with elevated privileges and compromise the VCO host. The latter, classified as an Exposure of Sensitive Information to an Unauthorized Actor, could enable an unauthenticated remote adversary to bypass the mitigation introduced to address a persistence mechanism based on symbolic links that had been observed in previous post-exploitation scenarios. CISA required U.S. Federal Civilian Executive Branch (FCEB) agencies to remediate these vulnerabilities by July 30 and August 10, 2026, respectively. Cisco also patched CVE-2026-20316 (CVSS 5.3), a 0-day Use of Hard-coded Password vulnerability affecting the web interface of Secure Firewall Management Center (FMC) that had been exploited in the wild (ITW) since at least July 2026. The presence of static credentials for a limited-privilege account could allow an unauthenticated remote attacker to gain access to vulnerable devices and view sensitive information. On July 29, 2026, CISA added the vulnerability to its KEV Catalog, requiring FCEB agencies to apply the available fixes by August 1, 2026. Finally, security researchers observed in-the-wild exploitation of CVE-2026-16723 (CVSS 9.0), a critical 0-day vulnerability in the Fastjson Java library affecting versions 1.2.68 through 1.2.83, including the latest release of the unsupported 1.x branch. The vulnerability, classified as Deserialization of Untrusted Data and Improper Input Validation, can be exploited by an unauthenticated attacker through specially crafted JSON requests that bypass the safeguards associated with the disabling of AutoType, ultimately enabling arbitrary code execution with the privileges of the affected application. The observed exploitation primarily targeted organizations in the United States operating in the financial, healthcare, information technology, and retail sectors, with a limited number of targets identified in Singapore and Canada. The publication of Proof-of-Concept (PoC) exploits further increases the likelihood of additional exploitation activity.
Major cyber incidents: data breaches, extortion activity, and attacks on critical infrastructure
Origin Energy Limited, an Australian company engaged in the generation, retail, and distribution of electricity and natural gas, confirmed a security incident involving unauthorized access to and disclosure of data relating to a number of customers. According to the company, the exposed financial information is incomplete and would not be sufficient to carry out unauthorized transactions or compromise customer accounts. An adversary identifying itself as John Doe claimed responsibility for the breach, stating that it possesses information relating to approximately 2 million customers and threatening to publish the data. Turning to India, on July 27, 2026, the state-owned Bank of Baroda confirmed a security incident resulting from the compromise of an employee’s email account, which enabled unauthorized access to certain data. The announcement followed the online publication of a dataset exceeding 700 GB allegedly belonging to the bank, reportedly containing customer identification and loan-related documents, as well as internal audit records. In addition, between July 26 and 27, 2026, a coordinated cyberattack targeted the operational technology (OT) of more than 30 community water systems in Minnesota, compromising control and automation systems and, in some cases, forcing operators to switch to manual operations. The municipalities of Braham, Plymouth, Maple Plain, and South St. Paul reported temporary disruptions affecting wells, treatment plants, water towers, pumping stations, and automated distribution network functions. No evidence emerged of water quality degradation, unauthorized modifications to chemical dosing, or physical damage to infrastructure. Authorities have not formally attributed the operation, and no ransom demands have been reported. Although the observed tactics bear similarities to previous campaigns against U.S. water infrastructure attributed to the CyberAv3ngers ecosystem, linked to the Cyber-Electronic Command of Iran’s Islamic Revolutionary Guard Corps (IRGC-CEC), no official connection has been established at this time. ShinyHunters claimed responsibility for compromising Ernst & Young (EY), alleging that, through a purported supply chain attack, it obtained valid credentials providing access to the company’s Jira, GitHub, and Azure environments. The group did not disclose what information was allegedly stolen but threatened to publish the data unless contacted by EY by July 31, 2026. The same group also claimed responsibility for breaching DentaQuest, one of the leading U.S. providers of dental insurance and public oral health programs. The company disclosed that, in May 2026, it detected unauthorized access to a limited portion of its network, specifically involving a network file share. ShinyHunters further claimed to have exfiltrated more than 234 GB of data, which was subsequently published on its leak site after ransom negotiations failed. Finally, Everest Team claimed responsibility for compromising Stadler Rail, the Swiss manufacturer of railway vehicles, signaling systems, and rail transport solutions. The company had previously disclosed that it had received and rejected a ransom demand of CHF 10 million.
Weekly Threats Report is Telsy’s weekly update featuring the main developments on cyber attacks and threat actors worldwide, produced by our Threat Intelligence & Response team.
The team is composed of analysts and security researchers with technical and investigative skills and internationally recognized experience.
Through continuous monitoring of cyber threats and geopolitical events, it produces and provides organizations with useful information to anticipate attacks and understand their scope, with the support of a trusted partner in the event of a cyber incident.
Learn more about our Cyber Threat Intelligence solution.
