CuraSec

tag: Russian-Apt · 4 items

2026-08-21 · Google Threat Intelligence · source ↗ #russian-apt#oauth-abuse#espionage
  • Engineer — Plan: OAuth consent-flow abuse by APT29-linked clusters is a real attack surface for any organization using third-party OAuth integrations; audit configured OAuth app permissions and enforce stricter conditional access policies to reduce the social-engineering foothold these groups exploit.
  • SOC/IR — Act: Three active Russian clusters are running persistent campaigns against high-value sectors using OAuth flow hijacking and captive-portal redirects — pull Google’s full IOC list, hunt for anomalous OAuth token grants or device-code auth attempts since mid-2025, and tune detections for captive-portal redirect chains tied to UNC7005 TTPs documented by Reliaquest and Microsoft.
  • Leader — Plan: If your organization falls in academia, aerospace/defense, government, or think tanks, queue a targeted user-awareness briefing on OAuth and device-code phishing before next quarter; the APT29 lineage of UNC6293 elevates this beyond routine phishing and warrants a conversation with your security team about protective intelligence coverage.
2026-07-24 · BleepingComputer · source ↗ #zimbra#russian-apt#email-security
  • Engineer — Act: CISA warning on active state-sponsored exploitation of a Zimbra zero-click vulnerability means patch status must be confirmed immediately — upgrade Zimbra Collaboration to the patched release and audit server logs for signs of prior compromise.
  • SOC/IR — Act: Void Blizzard (Laundry Bear) is actively combining phishing with this Zimbra exploit in live campaigns — hunt for anomalous Zimbra authentication events and email-sync activity tied to this actor since the campaign began, and request any IOCs from the CISA advisory.
  • Leader — Act: A CISA-attributed Russian espionage campaign targeting enterprise email warrants confirming this week whether Zimbra is in your environment, verifying engineering has applied the patch, and briefing leadership given the data-theft implications.
2026-07-24 · The Hacker News · source ↗ #zimbra#russian-apt#zero-day
  • Engineer — Act: If you run Zimbra webmail, patch to the latest release immediately — the exploit is zero-click (opening a message triggers it) and a joint NSA/CISA advisory confirms months of active state-actor abuse. Also review Zimbra access logs for bulk email-download activity over the past 90+ days.
  • SOC/IR — Act: Pull the NSA/CISA joint advisory for published IOCs and hunt for bulk email exfiltration patterns and anomalous 2FA-recovery-code access in Zimbra webmail logs; the campaign ran for months, so extend your look-back window accordingly.
  • Leader — Act: If Zimbra is in your webmail stack, confirm patch status with your engineering team this week and assess whether sensitive mailboxes were exposed; a joint NSA/CISA advisory on a months-long Russian espionage campaign stealing credentials and 2FA codes warrants a pre-emptive leadership brief before it surfaces in board news feeds.
  • Engineer — Plan: The advisory targets vulnerable and misconfigured routers — audit your edge router configurations against the joint advisory’s hardening guidance and prioritize patching any unmanaged or end-of-life devices on the network perimeter this quarter.
  • SOC/IR — Plan: A nine-nation joint advisory signals a documented campaign with TTPs worth operationalizing; pull the full advisory for any ATT&CK mappings and IOCs and build or tune detections for lateral movement originating from router-adjacent network segments.
  • Leader — Plan: A coordinated advisory from nine countries on Russian state targeting of critical infrastructure raises the threat posture for the quarter — assess whether your sector is named in the advisory and prepare a brief for leadership on edge-device exposure and any vendor dependencies in that space.