Threat Analysis: Zimbra Zero-Click RCE, Check Point Authentication Bypass, and the Helix Vishing Threat to UK SMBs

Threats & Attacks

Threat Analysis: Zimbra Zero-Click RCE, Check Point Authentication Bypass, and the Helix Vishing Threat to UK SMBs

Hello, Mauven here.

This is your Daily Threat Analysis for 24th August 2026.

Three things on the board this Monday. Two are confirmed actively exploited vulnerabilities. The third is a social engineering campaign that leaves no malware trace and is, for that reason, considerably more dangerous to organisations that think endpoint detection is a security strategy.


Priority One: Zimbra RCE Under Active Exploitation by Russian-Linked Actors

CISA added CVE-2025-66376 to its Known Exploited Vulnerabilities catalogue and ordered US federal agencies to patch within three days. That three-day window is the tell. CISA does not issue three-day deadlines for theoretical risks.

The vulnerability is a zero-click remote code execution flaw in Zimbra Collaboration Suite. Researchers at Palo Alto Unit 42 have been tracking the campaign behind the exploitation, designated CL-STA-1114, overlapping with activity attributed to the Russian threat actor known as Void Blizzard and LAUNDRY BEAR. The targets are government agencies, defence organisations, transportation, and financial sector entities across NATO member states, Ukraine, CIS countries, and Africa.

What the CISA advisory does not say is that this campaign has been running for some time, and the actor behind it has a documented history of systematic credential harvesting from webmail infrastructure. The exploitation of CVE-2025-66376 is not opportunistic scanning. This is a focused campaign against organisations of intelligence value.

What this means for UK SMBs. Most small businesses are not running Zimbra. But some are, particularly in the legal, accountancy, and professional services sectors where firms have historically maintained on-premises email infrastructure for compliance reasons, or where an IT provider set it up years ago and nobody has revisited the decision. If you are in that category, or if you provide IT services to organisations that might be, this is not a patch to schedule for next month.

The advisory also matters because it confirms that Zimbra infrastructure is being actively scanned and exploited at scale. Any organisation that appears on a NATO member state target list, even peripherally, through supply chain relationships, is potentially in scope.

Action required:

  • Check whether Zimbra Collaboration Suite is deployed anywhere in your environment, including hosted instances managed by a third party
  • Apply the vendor patch immediately
  • If you cannot patch immediately, restrict internet access to the Zimbra interface as a temporary measure and review access logs for anomalous authentication activity
  • If you have a managed service provider, ask them today whether any client infrastructure they manage is running Zimbra

Priority Two: Check Point SmartConsole Authentication Bypass, Exploitation Confirmed

Check Point has published a security advisory confirming active exploitation of CVE-2026-16232, an authentication bypass vulnerability in SmartConsole affecting Security Management, Multi-Domain Management, Quantum Security Gateway, and Gaia operating systems. Two further vulnerabilities, CVE-2026-62144 and CVE-2026-62145, are included in the same advisory.

The headline finding: an unauthenticated remote attacker can bypass SmartConsole login and gain full administrative access to an exposed Management Server. Full administrative access. To your firewall management interface.

Check Point’s own advisory is careful with its language. It notes that exploitation has been confirmed against “a limited number of customers with specific configurations where Management is exposed directly to the internet without IP restrictions.” Read that carefully. The “specific configuration” they are describing, a management interface with internet exposure and no IP allowlisting, is not an exotic edge case. It is the default state of a great many installations, particularly in organisations that added remote management capability during the pandemic and never revisited the access controls.

The NCSC has published guidance on securing network device management interfaces. The principle, that management planes should never be internet-exposed without strict IP restrictions, has been consistent for years. The fact that Check Point is now confirming exploitation of exactly this configuration tells you how widely that guidance has been applied.

What this means for UK SMBs. If your organisation uses Check Point products, or if your managed service provider manages Check Point infrastructure on your behalf, this requires attention today. The question to ask your IT provider is not “are we affected?” The question is “can you confirm that no Check Point management interface in our environment is internet-accessible without IP restriction?” Those are different questions and they require different answers.

For organisations that have outsourced their firewall management: you are not insulated from this risk by the outsourcing arrangement. You are exposed through it. If your provider manages your Check Point deployment, their configuration decisions are your security posture.

Action required:

  • Apply the Check Point security update immediately
  • Verify that all management server interfaces are restricted by IP allowlist
  • If internet-facing management was enabled at any point, review management server access logs for authentication attempts from unrecognised sources
  • Confirm with your MSP or IT provider that they have applied the patch across all managed Check Point deployments

Priority Three: Helix, Vishing and Device Code Phishing, No Malware Required

ReliaQuest has published research on a data extortion group called Helix, assessed to have emerged from the BlackFile and ShinyHunters ecosystem following BlackFile’s shutdown in April 2026. The TTPs are worth understanding in some detail, because this group is not doing anything that requires a sophisticated technical capability. What they are doing requires a telephone and some open-source research.

The Helix playbook involves three stages. First, vishing, telephone calls in which the attacker impersonates a manager or senior colleague by name, using information gathered from LinkedIn and company websites. The target of the call is typically a lower-level employee who has no reason to distrust a call that appears to come from someone they recognise. Second, device code phishing, the target is directed to enter a device code into a legitimate Microsoft authentication page, which grants the attacker persistent access to the victim’s Microsoft 365 account without requiring the victim’s password. Third, automated SharePoint exfiltration, once authenticated, the attacker uses tooling to systematically extract documents from SharePoint before the compromise is detected.

There is no malware in this chain. There is nothing for endpoint detection to catch. The authentication event is legitimate, the victim entered the code willingly. The SharePoint access is legitimate, the attacker is authenticated as the user. By the time the data has left the organisation, the only evidence is in Microsoft 365 audit logs, and only if those logs are being reviewed.

The advisory attributes Helix activity to multi-target campaigns. This is not selective targeting of specific organisations. These are broad campaigns designed to find whichever employees are susceptible to the social engineering component.

What this means for UK SMBs. The SMB exposure here is higher than it might appear. Larger organisations have security operations teams reviewing Microsoft 365 audit logs. Many small businesses do not. The vishing component is specifically designed to exploit the trust relationships that exist in smaller organisations, where staff are more likely to comply with an unusual request from someone they believe to be their manager, and less likely to have a formal verification procedure.

Device code phishing is not new. Microsoft has published documentation on it. But awareness among non-technical staff, which is the actual attack surface here, remains low.

Action required:

  • Brief all staff today on device code phishing: legitimate Microsoft processes do not require staff to enter codes based on an unsolicited telephone request
  • Establish a simple verbal verification procedure for any request that involves accessing systems or sharing credentials, a callback to a known number, not the number the caller provides
  • Review Microsoft 365 audit log retention settings; if unified audit logging is not enabled, enable it now
  • Consider Conditional Access policies that restrict or flag device code authentication flows, particularly for accounts with access to sensitive SharePoint content
  • If your organisation is on Microsoft 365 Business Basic or Standard, confirm with your IT provider whether Conditional Access is available in your licence tier and what compensating controls are in place

The Pattern This Week

Three separate threats. One common factor: all three exploit the gap between what organisations have configured and what they have documented. Zimbra instances that have not been reviewed in years. Management interfaces that were opened for convenience and never locked down. Microsoft 365 audit logs that are not being read.

None of these are novel attack vectors. The Zimbra campaign has been running for some time. The principle that management interfaces should not be internet-exposed has been established guidance for years. Device code phishing has been documented since at least 2020.

The adversaries know this. They are not looking for organisations with sophisticated defences. They are looking for organisations that have not done the basics.


Sources

SourceTitleURL
BleepingComputerCISA orders urgent patching of actively exploited Zimbra flawhttps://www.bleepingcomputer.com/news/security/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw/
Palo Alto Unit 42Global Webmail Espionage, CL-STA-1114 / LAUNDRY BEAR Zimbra campaignhttps://unit42.paloaltonetworks.com/russian-webmail-espionage/
Check Point BlogSecurity Advisory: Active Exploitation of SmartConsole Authentication Bypass CVE-2026-16232https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-check-point-smartconsole-authentication-bypass-cve-2026-16232/
op-c.netCheck Point SmartConsole Authentication Bypass (CVE-2026-16232)https://op-c.net/blog/check-point-smartconsole-authentication-bypass-cve-2026-16232/
ReliaQuestThreat Spotlight: Helix, A New Name in the Data Extortion Ecosystemhttps://reliaquest.com/blog/threat-spotlight-helix-new-name-in-data-extortion-ecosystem

Before the next story: if Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically. And if someone in your network needs the heads-up on any of what we covered today, the Zimbra patch, the Check Point issue, or the Helix vishing campaign, pass it along. The briefing is only useful if it reaches the people who can act on it.

Filed under

  • nation-state-attacks
  • credential-theft
  • social-engineering
  • remote-access
  • smb-security
  • vendor-risk
  • incident-response