Russian State-Supported APT LAUNDRY BEAR Exploits Zero-Day in Zimbra Webmail for Global Email Espionage

Russian state-supported cyber actors (LAUNDRY BEAR) have exploited a zero-day XSS vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite since July 2025 to exfiltrate 90 days of email, GAL, and authentication data via a view-only phishing technique, requiring only that victims open a malicious email in a vulnerable web client. Read more

A Practical Workflow for A Taiwan supplier appears in a security advisory; how should operations teams assess exposure? — 24 July 2026 Review

A Practical Workflow for A Taiwan supplier appears in a security advisory; how should operations teams assess exposure? — 24 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for Taiwan semiconductor and manufacturing supplier cyber risk review — 24 July 2026 Review

A Practical Workflow for Taiwan semiconductor and manufacturing supplier cyber risk review — 24 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for How to decide whether a Taiwan CERT vulnerability matters to your company — 24 July 2026 Review

A Practical Workflow for How to decide whether a Taiwan CERT vulnerability matters to your company — 24 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for What is KrCERT, and when should cloud teams act on South Korea alerts? — 24 July 2026 Review

A Practical Workflow for What is KrCERT, and when should cloud teams act on South Korea alerts? — 24 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for Hong Kong finance and cloud security signals worth escalating — 24 July 2026 Review

A Practical Workflow for Hong Kong finance and cloud security signals worth escalating — 24 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for Build a daily East Asia cyber signal review queue — 24 July 2026 Review

A Practical Workflow for Build a daily East Asia cyber signal review queue — 24 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for Route public cyber signals to the right team — 23 July 2026 Review

A Practical Workflow for Route public cyber signals to the right team — 23 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for Use the CISA KEV catalog to build an East Asia supplier patch watchlist — 23 July 2026 Review

A Practical Workflow for Use the CISA KEV catalog to build an East Asia supplier patch watchlist — 23 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more

A Practical Workflow for Keep monitor-only records useful without turning them into thin articles — 23 July 2026 Review

A Practical Workflow for Keep monitor-only records useful without turning them into thin articles — 23 July 2026 Review helps security, cloud, and supplier-risk teams keep an East Asia cyber or AI-risk signal under review when there is no fresh publish-ready news item. It explains how to preserve the original link, separate visible evidence from assumptions, and route unclear findings without inventing unsupported claims. Read more