STRATQUAD
CYBER THREAT INTELLIGENCE BRIEF
Daily Brief · 24 July 2026 · 24h windowRISKHIGH
StratQuad CTI Daily Brief, 24 July 2026
Compiled from 52 monitored sources · 285 articles reviewed

Today’s Briefing

The NCSC and international partners have exposed LAUNDRY BEAR, a Russian state-supported threat group, for a new zero-click phishing campaign targeting Zimbra Collaboration Suite users at Western organisations. Separately, Cisco Talos reports that Chaos ransomware operators are deploying msaRAT, a remote access tool that builds covert command and control channels by living off the browser, and Microsoft has detailed a North Korean supply chain compromise by Sapphire Sleet that injected a postinstall payload into the Mastra npm package. Six critical Mozilla Firefox and Thunderbird memory safety vulnerabilities disclosed today include CVE-2026-16408, an integer overflow in the audio and video playback component, and CVE-2026-60366, a critical flaw in Oracle Platform Security for Java affecting versions 12.2.1.4.0 and 14.1.2.0.0.

Top Stories

  1. Johnson Controls XAAP Android
  2. Don’t swing at everything
  3. Panduit IntraVUE
  4. Preview: Cisco Talos at Black Hat USA 2026
  5. UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations

Full brief available to subscribers

The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.

Get the brief at 07:00, every weekday.

The day's UK security intelligence, read and ranked so you start informed: the stories that matter, the IOCs your SIEM needs, and the actions worth taking first.

← All briefs