Zimbra Zero-Click RCE, Check Point Bypass, and Device Code Phishing
This episode examines three active threats demanding immediate attention from UK small businesses. First, a zero-click remote code execution vulnerability in Zimbra Collaboration Suite (CVE-2025-66376) under active exploitation by Russian-linked threat actors, with a three-day federal patch deadline from CISA. Second, an authentication bypass flaw in Check Point SmartConsole (CVE-2026-16232) allowing unauthenticated remote attackers full administrative access to exposed management servers. Third, a vishing and device code phishing campaign by the Helix data extortion group that requires no malware and leaves minimal forensic trace. The episode emphasises that all three threats exploit the gap between what organisations have configured and what they actually review. Practical actions include patching Zimbra immediately, verifying Check Point management interfaces are IP-restricted, enabling Microsoft 365 unified audit logging, and training staff on device code phishing recognition. The common thread is organisational discipline: knowing what is running in your environment, how it is configured, and whether anyone is reviewing the evidence of activity within it.
Chapters
IntroductionMauven introduces three threats for 24 August 2026: two confirmed, actively exploited vulnerabilities with patches available, and a social engineering campaign that leaves no malware trace. The third threat is identified as the most dangerous for UK small businesses reliant on endpoint detection alone.
Zimbra Zero-Click RCE Under Active ExploitationCISA has added CVE-2025-66376, a zero-click remote code execution flaw in Zimbra Collaboration Suite, to its Known Exploited Vulnerabilities catalogue with a three-day federal patch deadline. The vulnerability is being exploited by Russian-linked threat actor Void Blizzard (LAUNDRY BEAR) in a systematic credential harvesting operation targeting government, defence, transportation, and financial sector organisations across NATO member states. UK small businesses, particularly legal firms, accountancy practices, and professional services running on-premises email, must patch immediately, verify Zimbra deployment status, restrict internet access if patching cannot occur immediately, and review access logs for anomalous activity.
Call to ActionListeners are encouraged to follow the show and share the briefing with colleagues who can act on the information presented.
Check Point SmartConsole Authentication BypassCheck Point has confirmed active exploitation of CVE-2026-16232, an authentication bypass vulnerability in SmartConsole that allows unauthenticated remote attackers full administrative access to exposed Management Servers. Exploitation has been confirmed against customers with management interfaces exposed to the internet without IP restrictions. UK organisations using Check Point products must apply security updates immediately, verify all management interfaces are IP-restricted with documentation, review access logs for authentication attempts from unexpected sources, and confirm managed service providers have patched all deployments.
Helix Vishing and Device Code PhishingReliaQuest has documented a data extortion group named Helix running a three-stage attack requiring no malware: vishing calls impersonating managers using open-source research from LinkedIn and company websites, device code phishing directing employees to enter codes into legitimate Microsoft authentication pages to grant attackers persistent access tokens, and automated SharePoint exfiltration. The campaign leaves no endpoint detection evidence and is only visible in Microsoft 365 unified audit logs. UK small businesses must brief all staff on device code phishing, establish verbal verification procedures for credential-related requests, enable unified audit logging in Microsoft 365, and consider Conditional Access policies restricting device code authentication flows.
The Pattern This WeekAll three threats exploit the gap between what organisations have configured and what they have reviewed. Zimbra instances not audited since deployment, management interfaces opened for remote access and never locked down, and Microsoft 365 audit logs not being read represent ordinary accumulated drift rather than exotic failures. The adversaries target organisations that have not implemented basic controls, and the discipline required to close these gaps is organisational rather than technical.
ConclusionThe practical takeaway is to answer three questions immediately: is Zimbra running anywhere in your environment, is any network device management interface accessible from the internet without IP restriction, and is unified audit logging enabled in your Microsoft 365 tenant. If the answers are unknown, organisations must find out today.
Links
https://www.cisa.gov/known-exploited-vulnerabilities-cataloghttps://unit42.paloaltonetworks.com/https://www.checkpoint.com/advisories/https://www.ncsc.gov.uk/https://www.reliaquest.com/https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-device-code