Russian Laundry Bear group exploits Zimbra zero-day to steal email and 2FA codes

US agencies warn that Russian APT group Laundry Bear is actively exploiting CVE-2025-66376 against unpatched Zimbra Collaboration servers worldwide.

The Latest

Breaking News and Alerts

Europol takedown operation flags 4,340 URLs tied to the Com network

Europol identified thousands of horrific URLs linked to The Com network as part of an ongoing crackdown on the violent extremist youth group.

Spotlight

Cybersecurity Profiles and Stories

Adobe Acrobat browser extension flaw exposed WhatsApp chats on 329 million devices

A vulnerability chain in the Adobe Acrobat Chrome extension let any webpage silently steal WhatsApp Web chats from 329 million browsers without malware.

Google restricts powerful new Gemini Cyber AI to government partners only

Google DeepMind released Gemini 3.5 Flash Cyber, a specialized AI for vulnerability hunting, restricted to governments and trusted partners due to dual-use risks.

Check Point rushes fix for actively exploited SmartConsole bypass

Check Point patched a critical SmartConsole authentication bypass under active exploitation that gives attackers full admin access to security management servers.

NuGet package NewJson.Net delivers game cheats inside working library fork

A trojanized Newtonsoft.Json fork on NuGet smuggles game-rigging malware inside a fully functional serialization library to evade detection.

Features

Research and Thought Leadership