Product
TA488 Exploits Zimbra Mailservers with Half-Click Vulnerability CVE-2025-66376
2 rules 9 TTPs 3 CVEs 7 IOCsRussia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploited CVE-2025-66376, a critical XSS vulnerability in Zimbra Collaboration Suite webmail, for at least five months in 2025 via crafted emails to gain persistent access, exfiltrate user credentials, 2FA codes, and bulk emails from Ukrainian government and US defense industrial base targets.
CVE-2026-14191 WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
1 CVECVE-2026-14191 describes an out-of-bounds heap write vulnerability in WinRAR and UnRAR when processing RAR5 recovery volumes (.rev), allowing an unauthenticated attacker to achieve remote code execution on a victim's system by tricking a user into opening a specially crafted archive.
Microsoft Security Updates — July 2026
10 CVEs 227 IOCsRoundup of Microsoft security advisories published in July 2026.
FrostyNeighbor Targets Ukraine with Updated PicassoLoader Chain
2 rules 3 TTPs 5 CVEs 16 IOCsThe FrostyNeighbor threat actor is targeting Ukrainian governmental organizations with spearphishing emails containing malicious PDFs that deliver a JavaScript dropper (PicassoLoader) and ultimately a Cobalt Strike beacon.
WinRAR and 7-Zip Encryption Abuse for Data Exfiltration Preparation
3 rules 2 TTPsAdversaries use WinRAR or 7-Zip to create encrypted archives in preparation for data exfiltration, using command-line arguments to enable encryption functionality.
Windows Script Execution from Archive File
2 rules 3 TTPsThis rule detects attempts to execute Jscript/Vbscript files from archive files, a common method for delivering malicious scripts by identifying unusual parent-child process relationships where scripting utilities are launched from archive programs, indicating potential exploitation.