The Lyceum: Cyber Intelligence Daily — Jul 24, 2026
Photo: lyceumnews.com
Friday, July 24, 2026
The Big Picture
The freshest attacks share an uncomfortable theme: trusted connective tissue is becoming the target. Blockchain bridges obeyed stolen signatures, an enterprise design platform became an extortion pipeline, and a webmail preview pane quietly turned one message into lasting mailbox access.
What Just Dropped
The grounded vulnerability prefetch did not contain three confirmed disclosures from the past 24 hours with sufficient patch and CVSS data. Rather than recycle older CVEs into a 24-hour edition, this section is intentionally unpadded.
Today's Stories
[Not Yet in English] Two Crypto Bridges Lost $31.6 Million—One May Have Obeyed Every Rule
Russian-language publication Xakep reports that approximately $24.15 million was drained from the AFX bridge on Arbitrum and another $7.5 million from the Verus bridge on Ethereum. According to Blockaid’s preliminary analysis, five internet-connected AFX validator keys were compromised, producing enough legitimate signatures to authorize the withdrawals.
That distinction matters. If Blockaid’s assessment holds, AFX’s smart contracts may have worked as designed; the failure sat in the people, systems, and key-management processes trusted to tell those contracts what to do. Better code audits alone cannot solve that problem.
Xakep also reports that the Verus method resembled a May incident in which $11.58 million was taken and mostly returned—only for nearly all the recovered funds to be stolen again. The signal to watch is wallet or infrastructure overlap: a connection would point to coordinated bridge hunting, while none would suggest that weak bridge operations are simply plentiful enough to attract independent crews. (xakep.ru)
Clop Has Found Another Enterprise Data Warehouse to Empty
BleepingComputer reports that companies are receiving extortion messages associated with Clop after internet-facing PTC Windchill and FlexPLM systems were compromised. PTC’s advisory confirms that CVE-2026-12569 can permit unauthenticated remote code execution and says patches are available; the supplied CVE backbone does not yet provide an NVD score.
Windchill and FlexPLM often hold product designs, manufacturing specifications, bills of materials, and other intellectual property that remains valuable long after a password is changed. If Clop has industrialized this campaign, engineering data becomes the leverage—and patching late does not remove webshells, which are small server backdoors installed after entry.
Organizations with exposed systems should preserve logs, hunt for webshells, rotate credentials, and investigate access rather than treating the patch as the finish line. Clop naming victims or publishing engineering files would confirm that this is a broad platform-extortion wave rather than a limited set of intrusions.
A Zimbra Preview Pane Became a Russian Espionage Foothold
The United Kingdom’s National Cyber Security Centre and agencies from 15 partner countries disclosed that Laundry Bear—also tracked as Void Blizzard and TA488—used CVE-2025-66376 against Zimbra Collaboration Suite. On vulnerable systems, opening or previewing a crafted email in Zimbra’s Classic interface could execute malicious code without a link or attachment. (Laundry Bear’s ZimReaper steals email and creates its own mailbox password)
The campaign collected credentials, two-factor authentication recovery material, address books, and up to 90 days of email. More quietly, the operators could create application-specific passwords, preserving mailbox access through IMAP even after a user changed the main password.
That forces a different response from “patch and reset.” Zimbra administrators need to revoke unfamiliar application passwords, inspect mailbox-access records, and hunt for the indicators in the government advisory. If Laundry Bear shifts the same view-only technique to another webmail platform, this becomes reusable Russian tradecraft rather than a Zimbra-specific chapter.
Origin Energy Confirms Customer Data Was Stolen
Origin Energy has confirmed that customer records were accessed and leaked online, according to BleepingComputer. The exposed information may include names, addresses, birth dates, phone numbers, account details, and partial card or bank-account numbers.
Origin says those partial financial details cannot independently authorize payments or take over bank accounts. They can, however, make impersonation scams far more convincing: a caller who knows an address, birth date, and real utility account can sound distressingly legitimate.
A person using the name “John Doe” claims to possess data belonging to two million Origin customers, but Origin has not confirmed that figure and is still determining the affected population. Confirmation of that count—or disclosure of the compromised system—will reveal whether this was a contained exposure or one of Australia’s largest recent consumer-data breaches.
⚡ What Most People Missed
- TA458’s expanding webmail playbook: Proofpoint says TA458 has used “half-click” exploits against Zimbra, mDaemon, Roundcube, SOGo, and an obsolete Kerio deployment. The newly documented SOGo flaw, CVE-2026-8496, has no NVD score in the supplied backbone; the larger signal is that Russian-aligned operators are treating webmail servers as durable espionage infrastructure, not one-time inboxes.
- The mailbox password victims did not create: Proofpoint observed Laundry Bear creating an application-specific password called “ZimbraWeb.” That credential could preserve IMAP access after an ordinary password reset, making application-password review essential to incident response.
- Langflow’s federal deadline remains active: The Cybersecurity and Infrastructure Security Agency’s remediation deadline for actively exploited CVE-2026-0770 expires Friday. The backbone rates it CVSS 9.8 with operational exploitation; teams that cannot exclude compromise should rotate cloud and service credentials, not merely install the update.
- FortiSandbox is serious, but not fresh: CISA’s deadline for the actively exploited Fortinet flaws passed July 19, so the underlying action falls outside this edition’s 24-hour window. Any vulnerable FortiSandbox deployment is nevertheless overdue and should be investigated, not presented as a new July 24 emergency.
- The Microsoft Office alert circulating again is stale: CVE-2026-21509 is real and actively exploited, but Microsoft and CISA acted in January; the federal deadline passed February 16. There is no confirmed fresh emergency patch for that CVE in this edition’s reporting window.
From the Foreign Press
A WP-SHELLSTORM Server Exposed Data About Thousands of Attacks
Xakep reports that infrastructure associated with WP-SHELLSTORM exposed information concerning thousands of attacks. The available research does not establish the affected organizations or the full contents of the exposed data, so those details remain unresolved. If defenders can extract targeting or payload patterns from the server, an attacker’s operational mistake could become a useful detection map. Source: Xakep — Russian. No English-language coverage confirmed at time of publication.
A Critical Zilliqa Flaw Could Expose Private Keys
Xakep reports a critical vulnerability affecting Zilliqa that can permit theft of private keys. Private-key compromise is more damaging than an ordinary account breach because the credential itself authorizes blockchain transactions; changing a website password does not undo it. The key signal will be whether Zilliqa publishes affected versions, patches, and evidence of exploitation. Source: Xakep — Russian. No English-language coverage confirmed at time of publication.
Adobe Acrobat’s Chrome Extension Could Reach Into WhatsApp Web
Xakep reports that a flaw dubbed HermeticReader in Adobe Acrobat’s Chrome extension allowed access to WhatsApp messages and contacts. The risk comes from privilege collision: an extension trusted to handle documents may share a browser environment with far more sensitive applications. Confirmation of exploitation would turn this from an extension-permissions warning into a browser-compartmentalization problem. Source: Xakep — Russian. No English-language coverage confirmed at time of publication.
📅 What to Watch
- If Clop publishes Windchill engineering files, it means product-lifecycle platforms have become repeatable extortion targets alongside managed file-transfer systems.
- If the AFX and Verus wallets converge, it means bridge operators are facing a coordinated key-management campaign rather than two unrelated failures.
- If Origin confirms the two-million-customer claim, utility records will become a major Australian phishing dataset with value well beyond payment fraud.
- If new Laundry Bear infrastructure appears after the joint advisory, it means the group expects slow Zimbra remediation to outweigh the cost of burning its domains.
- If TA458’s SOGo exploit receives a patch and is followed by scanning, defenders will have evidence that obscure webmail platforms are becoming the next opportunistic target class.
- If application-specific passwords remain active after Zimbra password resets, organizations may discover that “remediated” mailboxes are still quietly compromised.
The Closer
A blockchain bridge obediently opening the vault, Clop rummaging through the engineering cabinet, and a preview pane handing Moscow a spare mailbox key.
The most unsettling credential in the issue is still “ZimbraWeb”—because apparently espionage persistence now comes with a default-looking label.
Patch carefully; hunt afterward.
Forward this to whoever still thinks changing the password ends the incident.
⚡ EDGE Signals
The following signals appeared in the adversarial edge sweep but were not carried forward in the primary synthesis:
- The uncomfortable through‑line: AI orchestration middleware has quietly become high‑value initial‑access infrastructure, like web frameworks a decade ago[1][6][7][8]. Earlier this month, the JadePuffer campaign already showed that an LLM‑driven ransomware run was bootstrapped via Langflow authen
- CISA has ordered immediate patching for two critical Fortinet FortiSandbox vulnerabilities, CVE‑2026‑39808 and CVE‑2026‑25089, after confirming they’re being actively exploited for unauthenticated remote code execution[2]. Both flaws are low‑complexity command‑injection bugs that require no user int
- A batch of high‑severity Microsoft cloud CVEs landed today with almost no fanfare: Azure DNS (CVE‑2026‑58275) and Azure Key Vault (CVE‑2026‑62825) both carry CVSS 10.0 scores for elevation‑of‑privilege flaws in core control‑plane services[9]. Microsoft Exchange Online has a CVSS 10.0 tampering vulne
- This looks less like random noise and more like a coordinated drop of cloud‑control vulnerabilities that could become the next chaining toolkit for sophisticated actors[9]. In practice, a Copilot RCE combined with Exchange Online or Graph bugs starts to blur the line between “app exploit” and “t
- [2] CISA urges immediate action on actively exploited Fortinet flaws
URL: https://radar.offseq.com/threat/cisa-urges-immediate-action-on-actively-exploited--827afffbcb184f3e
Snippet: Two critical vulnerabilities in Fortinet FortiSandbox were actively exploited in the wild, allowing unauthen