Russian threat actors exploit an OWA vulnerability to maintain mailbox access even after credential rotation, targeting critical infrastructure and government entities in the USA and Europe.
Laundry Bear exploits an unpatched Zimbra security vulnerability using “half-click” phishing emails that are triggered by opening or previewing a message to attack US and Ukrainian targets.
A zero-day vulnerability in Zimbra enabled Russian attackers to exfiltrate 90 days of email history, directories, stored passwords, and 2FA recovery codes by simply opening a message.
AI agents enable cybersecurity teams to scale threat detection, but grant attackers the same automation capabilities—while securing AI-powered systems is hampered by their unpredictability and connectivity requirements.