Cyware Daily Threat Intelligence - July 24, 2026

Attackers are slashing through healthcare supply chains across EMEA, forcing hospitals, clinics, and their partners into crisis as ransomware groups steal 40 TB of data tied to 450 million patient records. Cyware spotlights how a single breach at American Hospital Dubai echoes the $2.87 billion fallout from Change Healthcare in the US, where 40% of medical claims processing ground to a halt. The practical impact: delayed care and administrative paralysis as critical systems go dark.
A critical flaw in Splunk Enterprise is letting attackers seize control of security monitoring hubs with a single unauthenticated request. As CISA issues urgent patching directives for CVE-2026-20253 (CVSS 9.8), organizations face the risk of full compromise as attackers exploit exposed PostgreSQL endpoints to run code as the splunk user. The threat is active and spreading.
Russian espionage groups are turning Zimbra email servers into a goldmine, siphoning the last 90 days of sensitive communications from Western defense and government targets. Using zero-click and half-click exploits tied to CVE-2025-66376, attackers bypass user interaction, exfiltrating emails, passwords, and even 2FA tokens. Cyware.com tracks the campaign’s pivot from Ukraine to NATO members.
Top Malware Reported in the Last 24 Hours
Healthcare Ransomware Surge Across EMEA Supply Chains
Ransomware attacks targeting healthcare organizations across the EMEA region are escalating, with attackers focusing on hospitals, clinics, and their supply chains. Ransomware groups exfiltrate 40 TB of data tied to 450 million patient records from American Hospital Dubai and disrupt operations at Spire Healthcare, NRS Healthcare, and Genie Healthcare. Attackers use extortion, data theft, and system paralysis to pressure victims. Infection vectors include direct compromise of healthcare IT and supply chain partners. The attacks impact healthcare and supporting sectors across EMEA and Latin America, with the Kazu group emerging in Latin America. The report references the ALPHV/BlackCat attack on Change Healthcare, which resulted in over six terabytes of data stolen, a $22 million ransom paid, and $2.87 billion in damages after disruption to 40% of US medical claims processing.
Clop Exploits Windchill Flaw for Theft
Clop is a ransomware group leveraging CVE-2026-12569 to target PTC Windchill and FlexPLM systems for remote code execution and data exfiltration. Clop uses this access to steal sensitive engineering and business data, bypassing traditional encrypt-and-extort tactics. Clop exploits internet-facing servers to deploy JSP webshells and maintain persistent access. The group targets aerospace, defense, automotive, and medtech sectors, where stolen designs and regulated data can trigger operational and legal consequences. ReliaQuest reported the campaign, with CISA and Germany’s BSI issuing urgent warnings as the campaign unfolds.
TriBack Loader and TAG-195 Expand Kits
TriBack Loader is a stealthy shellcode loader tied to the JadeProx intrusion cluster and attributed to Chinese threat actors, designed to evade modern EDR by blending with signed binaries and manipulating Windows callback behavior. TriBack Loader leverages phishing lures, including fake Anthropic Claude portals, and targets entities in South-East Asia and Latin America, such as a Vietnamese public hospital and Malaysia’s Ministry of Foreign Affairs. TriBack Loader uses techniques like unusual InitOnceExecuteOnce, TimerQueue timers, and EtwpCreateEtwThread to evade detection. Infection occurs via phishing emails and malicious websites. The loader targets government and legislative bodies, including Honduras’ National Congress. TAG-195 (also known as Golden Chickens or Venom Spider) has introduced four new malware families—TinyEgg, ChonkyChicken, a modularized ChonkyChicken variant, and ChromEggscalator—expanding its malware-as-a-service ecosystem.
Top Vulnerabilities Reported in Last 24 hours
CVE-2026-20253: Splunk Zero-Day Enables Unauthenticated Server Takeover (CVSS 9.8)
CVE-2026-20253 is a critical remote code execution vulnerability in Splunk Enterprise (CVSS 9.8) that allows unauthenticated attackers to execute code remotely. Successful exploitation lets attackers perform arbitrary file writes and run code as the splunk user, risking full system compromise. Attackers are actively exploiting this vulnerability in the wild. CISA has issued urgent patching directives. The issue resides in a PostgreSQL sidecar service with exposed endpoints. A fix is available in versions 10.2.4+, 10.0.7+, and 10.4.x.
CVE-2026-12569: Clop Ransomware Hits PTC Windchill Servers
CVE-2026-12569 is a critical remote code execution vulnerability in PTC Windchill and FlexPLM, exploited by Clop ransomware operators to gain persistent access and steal high-value product design data. Exploitation enables attackers to deploy JSP webshells and maintain control over compromised servers. The vulnerability is being actively exploited in the wild. ReliaQuest reported the campaign, with warnings from CISA and Germany’s BSI. Affected sectors include aerospace, defense, automotive, and medtech. A patch is available from PTC.
Linux RefluXFS Bug Enables Local Root
The Linux kernel vulnerability dubbed RefluXFS is a race condition in the filesystem allocation layer affecting systems using the XFS filesystem with reflink enabled. RefluXFS allows an unprivileged local user to escalate privileges to root by overwriting critical files such as /etc/passwd or SUID-root binaries. No active exploitation has been reported. The flaw was discovered with assistance from the AI model Claude Mythos. The vulnerability affects distributions including RHEL, CentOS Stream, Oracle Linux, Rocky/AlmaLinux, CloudLinux, Amazon Linux, and Fedora Server. Patches are available, and systems require a reboot after updating.
Top Threat Actors Reported in Last 24 hours
Laundry Bear Zero-Clicks Zimbra for Email
Laundry Bear (also tracked as Void Blizzard or UAC-0190), is a Russian state-supported espionage group suspected of targeting Western organizations for intelligence collection. Laundry Bear exploits a zero-click flaw in Zimbra email servers, specifically CVE-2025-66376, to execute JavaScript embedded in HTML emails automatically. Laundry Bear uses the “beehive” exploit and the Flowerbed collection framework to exfiltrate data over DNS and HTTPS, and adversary-in-the-middle kits to steal credentials and session cookies. Laundry Bear targets defense contractors, government agencies, and organizations running Zimbra, resulting in loss of the last 90 days of emails, passwords, GAL data, and 2FA tokens. The campaign began with Ukrainian victims and expanded to NATO members. Impersonation domains include mailnalysis[.]com, emailanalytics[.]com[.]ua, zimbrastat[.]com, zimbra-metadata[.]com, istc-cloud[.]com, and zmailanalytics[.]com.
TA488 Hits Zimbra via Half-Click
TA488, a Russian-aligned threat actor linked to the Void Blizzard cluster, is suspected of conducting espionage campaigns against government and defense organizations. TA488 exploits the same CVE-2025-66376 flaw in Zimbra, using “half-click” messages that trigger malicious code when an email is opened. TA488 uses adversary-controlled and compromised email accounts to deliver exploit-laden messages and deploys the ZimReaper malware for reconnaissance and data theft via DNS queries. TA488 targets Ukrainian government entities and US government and defense organizations, exposing sensitive planning and procurement information. The campaign has been active since September 2025, as reported by Proofpoint.
Frequently Asked Questions
What is ALPHV/BlackCat? Ransomware attacks on healthcare organizations across the EMEA region are escalating, with attackers increasingly pressuring not just hospitals and clinics but the wider supply chain they depend on. The wave has already produced outsized breaches, including American Hospital Dubai, where attackers stole 40 TB of data tied to 450 million patient records, alongside incidents affecting Spire Healthcare, NRS Healthcare, and Genie Healthcare.
What is Clop? Clop is actively exploiting CVE-2026-12569 in PTC Windchill and FlexPLM, using the access for remote code execution and data exfiltration rather than a purely encrypt-and-extort play. It turns enterprise product lifecycle systems into a direct pipeline for stealing sensitive engineering and business data, raising the stakes for firms that depend on these platforms to run day-to-day operations.
What is TriBack Loader? TriBack Loader is a stealthy shellcode loader tied to the JadeProx intrusion cluster and attributed to Chinese threat actors, and it is designed to slip past modern EDR by blending in with signed binaries and obscure Windows callback behavior. It targets entities in South-East Asia and Latin America—including a Vietnamese public hospital and Malaysia’s Ministry of Foreign Affairs—while also showing phishing activity aimed at Honduras’ National Congress and AI-themed lures such as fake Anthropic Claude portals.
What is CVE-2026-20253? A critical zero-day in Splunk Enterprise (CVE-2026-20253, CVSS 9.8) lets an unauthenticated attacker run code remotely, risking full compromise of systems that often sit at the center of security monitoring. The weakness sits in a PostgreSQL sidecar service, where exposed endpoints allow attackers to trigger unauthorized file operations by sending a crafted request to the restore endpoint, potentially leading to arbitrary file writes and code execution as the splunk user.
What is CVE-2026-12569? Clop ransomware operators are exploiting a critical flaw in PTC Windchill and FlexPLM (CVE-2026-12569) to execute code remotely and steal data from organizations that rely on these systems to manage high-value product designs. ReliaQuest reported that attackers can leverage the bug to gain a foothold and deploy a JSP webshell, a move that can turn an internet-facing server into a persistent access point for data theft.
What is RefluXFS? A Linux kernel vulnerability dubbed RefluXFS allows an unprivileged local user to escalate privileges to root on systems using the XFS filesystem with reflink enabled, putting multi-tenant and shared environments at particular risk. The issue is described as a race condition in the kernel’s filesystem allocation layer, and exploitation can enable overwriting critical files such as /etc/passwd or SUID-root binaries to seize full control of a machine.
What is Laundry Bear? Laundry Bear (also tracked as Void Blizzard or UAC-0190), a Russian state-supported espionage group, is exploiting a zero-click flaw in Zimbra email servers to siphon sensitive mail from Western targets. They abuse CVE-2025-66376, a cross-site scripting (XSS) bug in Zimbra Collaboration Suite’s Classic UI that can let JavaScript embedded in HTML emails execute automatically, enabling theft with no user interaction beyond viewing the message.
What is TA488? TA488, a Russian-aligned threat actor linked in reporting to the Void Blizzard cluster, is exploiting the same Zimbra bug to steal emails and maintain access inside high-value government environments. They use “half-click” messages where opening an email can be enough to trigger malicious code, leveraging the CVE-2025-66376 weakness in Zimbra’s client-side handling of malicious content.