Today’s Briefing
The NCSC and international partners have exposed LAUNDRY BEAR, a Russian state-supported threat group, for a new zero-click phishing campaign targeting Zimbra Collaboration Suite users at Western organisations. Separately, Cisco Talos reports that Chaos ransomware operators are deploying msaRAT, a remote access tool that builds covert command and control channels by living off the browser, and Microsoft has detailed a North Korean supply chain compromise by Sapphire Sleet that injected a postinstall payload into the Mastra npm package. Six critical Mozilla Firefox and Thunderbird memory safety vulnerabilities disclosed today include CVE-2026-16408, an integer overflow in the audio and video playback component, and CVE-2026-60366, a critical flaw in Oracle Platform Security for Java affecting versions 12.2.1.4.0 and 14.1.2.0.0.
Top Stories
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.
Get the brief at 07:00, every weekday.
The day's UK security intelligence, read and ranked so you start informed: the stories that matter, the IOCs your SIEM needs, and the actions worth taking first.