Zimbra Exploitation Meets Seychelles Leak Campaign

Events tracked
229
Critical exposure
73

Summary

Email infrastructure and public-sector data exposure converged into the day's most consequential defensive problem. A webmail campaign showed how long an unpatched client-side flaw can remain operational, while coordinated leak claims against one government demonstrated how a single actor can turn many agencies into one reputational crisis. The practical priority is to combine rapid edge-system patching with identity telemetry that can expose browser-mediated command channels and account abuse.

Today's developments

Actor p2wnz claims a coordinated series of breaches against Seychelles public bodies, including the Police Force, Revenue Commission, Ministry of Lands and Housing, Ministry of Fisheries, Agriculture and Blue Economy, Government Information Services, Seychelles Qualifications Authority, the City of Victoria, the Seychelles Trade Portal and the SWIOFish3 project. The claims have not been independently verified, but their concentration across ministries, policing, taxation and local administration makes the campaign materially broader than a single-site compromise.

Several other forum claims widen the exposure picture. Beregini claims breaches against Italy's Agenzia Industrie Difesa and Switzerland's RUAG Defence; LauraAllen claims data from US health insurer MagMutual and PayLow Pro; and jamboman claims airline data linked to Turkish Airlines and EL AL. Hackero$ claims Mexican public-sector compromises involving a procurement committee, the state professions directorate and a Michoacan cultural institution. 313team claims a leak involving Iraqi telecom operators Asiacell and Zain Iraq, while FINJEL claims a breach of an Indonesian public health center. Each remains an alleged actor statement rather than a confirmed incident.

Industry reporting supplied concrete exploitation detail. Government agencies and Unit 42 described Laundry Bear using a zero-click Zimbra technique and JavaScript injection against Western mailboxes; reporting says the zero-day operated for five months before a November 2025 patch and exploitation continued against vulnerable systems. Check Point patched CVE-2026-16232, a CVSS 9.3 SmartConsole authentication bypass reported as exploited in the wild. Researchers also disclosed CVE-2026-64600, a Linux XFS flaw that can let a local unprivileged user overwrite root-owned files on default RHEL-family installations.

Cisco Talos described Chaos ransomware deploying the Rust-based msaRAT implant, which drives headless Chrome or Edge and sends the implant's local traffic through 127.0.0.1 rather than opening its own outbound connection. Separate researchers reported AgentForger, a flaw that could insert and remotely control an invisible agent inside an organization, and a Claude Cowork sandbox escape that could let an agent read or write Mac files outside its Linux virtual machine. Origin Energy confirmed customer data was compromised and said it was still determining the affected population. Microsoft's quarterly review linked disruption of Tycoon2FA to declines in several phishing techniques while warning that attackers were expanding Teams-based social engineering and automated multi-stage chains.

Threat landscape signals

The feed recorded 229 events, six more than the prior day, but critical exposure claims fell from 83 to 73. The category mix changed sharply: ransomware rose from 23 to 54, while data breaches fell from 59 to 44; data leaks increased from 24 to 29 and DDoS activity from 18 to 23. That shift makes endpoint execution and recovery readiness more urgent even though the total volume barely moved.

The top three actors -- The Gentlemen, MARKET FLAZZ and p2wnz -- account for 54 events, or 23.6% of the total. Government Administration and Government and Public Sector together contributed 43 events, while the United States led the country table with 31, followed by France with 15 and Indonesia with 12. Defenders running Zimbra or Check Point management products should verify patch state and hunt for abnormal webmail scripts, unexpected SmartConsole authentication and headless browser processes on servers; identity teams should also review Teams-originated contact and credential-stuffing indicators rather than relying on email-only controls.

All incidents are reported as alleged claims by threat actors and have not been independently verified by GrayscaleInsight.

Threat intelligence is reported for security awareness purposes only and does not constitute endorsement of any actor, group, or activity.

Recent editions