ZeroFox Daily Intelligence Brief - July 24, 2026
|by Alpha Team

ZeroFox Daily Intelligence Brief - July 24, 2026
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Russian APT “Laundry Bear” Exploits Zimbra Flaw in Espionage Campaign
- Critical ChatGPT Workspace Flaw Enables Unauthorized AI Agents
- Chaos Ransomware Group Uses Custom Backdoor to Hide C2 Traffic
Russian APT “Laundry Bear” Exploits Zimbra Flaw in Espionage Campaign
Source: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a
What we know: Russia-linked advanced persistent threat (APT) group “Laundry Bear” has been targeting organizations running Zimbra Collaboration Suite (ZCS) in an espionage campaign. The group exploited a now-patched zero-day vulnerability, CVE-2025-66376, in Zimbra webmail.
Context: The campaign uses phishing emails to trigger a view-based exploit, requiring victims to open a malicious email for account data to be stolen. The exploit then attempts to steal the victim's last 90 days of emails, Global Address List (GAL), credentials, two-factor authentication tokens, and application passcodes, while also establishing persistent access. The indicators of compromise are listed here.
Analyst note: By eliminating the need for victims to click links or open attachments, this technique reduces reliance on user behavior, likely making it a more reliable initial access vector. Additionally, it is likely to be adopted beyond state-sponsored operations by financially motivated threat actors to improve the success of email-centric intrusion campaigns.
Critical ChatGPT Workspace Flaw Enables Unauthorized AI Agents
What we know: A critical vulnerability, dubbed AgentForger, was discovered in OpenAI's ChatGPT Workspace Agents that enabled an attacker to implant a remotely controlled autonomous AI agent inside a victim organization’s workspace with a single phishing click. OpenAI has reportedly since patched the vulnerability.
Context: The flaw resided in ChatGPT's Agent Builder, which accepted attacker-controlled instructions embedded within a weaponized URL. When an employee with workspace agent access clicked the link, the Builder would autonomously create, configure, and publish a malicious agent using the victim's existing connected applications, without triggering any additional authentication prompts.
Analyst note: As organizations increasingly rely on AI agents for daily workflows, threat actors are very likely to exploit agent infrastructure for hidden and persistent access.
Chaos Ransomware Group Uses Custom Backdoor to Hide C2 Traffic
Source: https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html
What we know: The Chaos ransomware group is reportedly using a new Rust-based backdoor, dubbed msaRAT, to hide command-and-control (C2) communications by routing them through legitimate Chrome or Edge browsers.
Context: Threat actors gain initial access through malicious emails or voice phishing (vishing) to install remote management software. Threat actors then download a malicious Windows update (MSI), which loads msaRAT (lib.dll) directly into system memory. The malware uses Chrome's developer tools to hide communication with the attacker's server.
Analyst note: This is the first observed use of the custom malware msaRAT by the Chaos ransomware group, suggesting the group is developing custom intrusion capabilities to improve stealth, persistence, and evasion of network monitoring prior to ransomware deployment. The backdoor is likely to enable threat actors to maintain covert access, conduct reconnaissance, move laterally, and meticulously profile the target to maximize extortion leverage.
DEEP AND DARK WEB INTELLIGENCE
Spear user xpl0itrs: A moderately credible threat actor "xpl0itrs" has advertised data allegedly associated with RapidFort, a U.S.-based cybersecurity company, on the English-language dark web forum Spear. According to the threat actor, the alleged dataset includes U.S. Department of Defense (DoD)-related information and comprises approximately 569 GB of data containing 140,061 files from 48 Amazon S3 buckets.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2026-16232: This is an actively exploited and patched authentication bypass vulnerability in Check Point SmartConsole. The flaw enables unauthenticated attackers to obtain an application login token, authenticate with administrator privileges, and modify security configurations and security policies. Successful remote exploitation requires the Management Server IP to be internet-accessible and Trusted Clients (GUI clients) to have no restrictions.
Affected products: The affected products are listed in this advisory.
Tags: DIB, tlp:green