The CyberWire Daily Podcast 7.24.26
Ep 2600 | 7.24.26

Laundry Bear gets the spin cycle.

Transcript

Laundry Bear snuffles through unpatched Zimbra Collaboration servers. The State Department puts visa restrictions on cybercriminals. Oracle drops a record 1,449 security patches. Researchers disclose a critical vulnerability in OpenAI’s ChatGPT Workspace Agents. A new benchmark evaluates frontier AI model malware reverse engineering. LunchPoke uses the Notepad++ application to establish persistence. A Swiss rail manufacturer refuses to pay the ransom. Dave Bittner sits down with Maria Varmazis, host of T-Minus Space Cyber Briefing, to discuss the show's evolution into CyberWire's weekly space cyber briefing. The AI goes to space.

Today is Friday July 24th 2026. I’m Dave Bittner Maria Varmazis. And this is your CyberWire Intel Briefing.

Laundry Bear snuffles through unpatched Zimbra Collaboration servers. 

CISA is warning that the Russian state-sponsored group Laundry Bear, also known as Void Blizzard, is targeting organizations using unpatched Zimbra Collaboration servers. The attackers exploit CVE-2025-66376, a cross-site scripting vulnerability that allows malicious JavaScript embedded in HTML emails to execute automatically when messages are viewed, enabling theft of emails, credentials, address books, and two-factor authentication tokens. The campaign also creates Zimbra application passcodes to maintain access while bypassing multi-factor authentication. Stolen data is exfiltrated over DNS and HTTPS, and the group also uses adversary-in-the-middle phishing sites that impersonate Zimbra login portals. CISA urges organizations to patch Zimbra, review indicators of compromise, investigate suspicious authentication activity, revoke unauthorized application passcodes, and adopt phishing-resistant multi-factor authentication where possible.

The State Department puts visa restrictions on cybercriminals. 

The State Department has announced new visa restrictions targeting individuals involved in foreign cybercrime networks, along with their immediate family members. Secretary of State Marco Rubio unveiled the policy during a visit to Southeast Asia, where industrial-scale scam centers have become a major regional concern. The restrictions apply to people responsible for or complicit in cyber-enabled crimes, including online scams and sextortion, and build on President Trump’s executive order aimed at combating cybercrime and fraud. Rubio said many of these operations are tied to Chinese transnational criminal groups engaged in human trafficking, money laundering, and financial scams that cost Americans an estimated $10 billion in 2024. The administration says the new policy is intended to deter cybercriminals by limiting their ability to travel to the United States.

Oracle drops a record 1,449 security patches. 

Oracle has released a record 1,449 security patches as part of its quarterly Critical Patch Update, reflecting both the company’s extensive product portfolio and its increased use of artificial intelligence for vulnerability discovery. Security experts say the volume is less an indication of poor code quality than a growing trend toward AI-assisted bug hunting, which is also driving larger patch releases across the industry. Oracle recently introduced monthly Critical Security Patch Updates to deliver fixes for the most urgent vulnerabilities between its quarterly releases. Among the highest-priority flaws are several critical vulnerabilities affecting Oracle Fusion Middleware and Oracle Database Server, including bugs that could allow unauthenticated system compromise or remote code execution. Experts urge organizations to prioritize patching and use automated patch management tools where possible.

Researchers disclose a critical vulnerability in OpenAI’s ChatGPT Workspace Agents. 

Security researchers at Zenity Labs disclosed a now-patched critical vulnerability in OpenAI’s ChatGPT Workspace Agents, dubbed “AgentForger,” that could have allowed attackers to create and remotely control invisible AI agents inside an organization’s ChatGPT workspace. The attack relied on phishing a logged-in user into clicking a specially crafted URL that abused the Agent Builder’s initialization process to automatically create an autonomous agent with attacker-defined instructions. If the victim already had authorized connectors, such as Gmail or Outlook, the agent could execute commands delivered by email, access sensitive data, impersonate users, and perform other actions without additional authorization prompts. Zenity reported the issue to OpenAI, which acknowledged the vulnerability and deployed a fix within three days, preventing further exploitation of the flaw.

A new benchmark evaluates frontier AI model malware reverse engineering. 

SentinelOne has introduced a new benchmark to evaluate how well frontier AI models handle long-term malware reverse engineering, using its investigation of the Fast16 malware as a real-world test case. Rather than measuring isolated tasks, the benchmark assesses whether models can adapt as new evidence overturns earlier conclusions. Among the models tested, GPT-5.6 Sol was the only one to successfully complete all eight investigation stages. Researchers found that while other models demonstrated strong technical analysis, they struggled to recover from incorrect assumptions. SentinelOne concluded that human reverse engineers remain essential, as even the best-performing model made significant errors and still required expert oversight.

LunchPoke uses the Notepad++ application to establish persistence. 

Ukraine’s CERT has identified a campaign by the UAC-0099 threat group that uses the legitimate Notepad++ application alongside a malicious plugin called LunchPoke to establish persistence on compromised systems. The attack begins with a phishing-delivered VBS script that downloads an archive containing Notepad++, a malicious DLL disguised as a plugin, and additional malware components. When Notepad++ launches, it loads the malicious plugin, which creates scheduled tasks, extracts additional payloads, and deploys the BurnyBear and MatchBoil V2 malware loaders. CERT-UA attributes the activity to UAC-0099, a group previously linked to providing initial access for Sandworm operations. Administrators are advised to update Notepad++, WinRAR, and 7-Zip to current versions and monitor for suspicious scheduled tasks and malicious plugin activity.

A Swiss rail manufacturer refuses to pay the ransom. 

Swiss rail manufacturer Stadler Rail says it will not pay a 10 million Swiss franc, about $12.3 million, ransom after the Everest ransomware group stole technical documents from a supplier’s file-sharing platform. The company said the breach resulted from compromised supplier credentials and did not affect Stadler’s own systems, operations, or customer data. Production remains unaffected, and there has been no impact on trains in service. Stadler has filed a criminal complaint and says it will not negotiate with the attackers. This marks the company’s second public extortion attempt in recent years, following a similar incident in 2020. Security experts note that paying ransoms often fails to end extortion, with many organizations later facing additional demands from the same attackers.

In fact, a new Proofpoint survey of 953 organizations found that more than one-third of companies that paid a ransomware demand were later targeted with a second extortion attempt. The findings reinforce long-standing guidance from governments and cybersecurity experts that paying a ransom does not guarantee stolen data will be deleted or attacks will end. Researchers say ransomware groups increasingly rely on repeated extortion, often retaining stolen data even after payment. Recent incidents, including breaches at Klue and Change Healthcare, illustrate how victims can remain vulnerable despite paying, underscoring the risks of negotiating with cybercriminals.

 

After the break, we're bending the space-time continuum just a little. Before Dave left, he turned the tables and interviewed me about why space cybersecurity deserves more attention. And the AI goes to space. Stay with us. 

Normally, this is where Dave would introduce his interview. Since I'm filling in for him today... I'll just introduce myself. Before Dave left, he sat down with me to talk about why space cybersecurity deserves more attention, here’s our conversation. 

If you enjoyed this conversation with Dave and I, and you want to hear part one, check out the show notes. 

The AI goes to space. 

NASA’s Jet Propulsion Laboratory has demonstrated that artificial intelligence doesn’t need a warehouse full of GPUs to earn its place in orbit. Researchers successfully ran Google’s lightweight Gemma 3 language model aboard Loft Orbital’s YAM-9 satellite, where it analyzed images captured in space and answered natural language questions about what it saw. The NAVI-Orbital system lets scientists guide image analysis with simple prompts instead of complex spacecraft commands, a shift that could make satellites far easier to operate. Beyond convenience, onboard AI could overcome bandwidth limitations by sending concise text summaries instead of massive image files, speeding applications like wildfire detection. For now, the model is safely isolated from flight controls, so no chatbot is flying the spacecraft just yet. Still, the demonstration suggests future satellites, and perhaps even astronauts, could someday have an AI companion ready to help, rather than just admire the view.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

This week on Research Saturday, Dave sits down with Ondrej Kubovič (Andre kuh-VO-vic), Security Awareness Specialist from ESET, as they discuss their research on "FrostyNeighbor: Fresh mischief and digital shenanigans." That’s Research Saturday, check it out. 

And that’s the CyberWire Daily, brought to you by N2K CyberWire.

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music and sound design by Elliott Peltzman. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.