Security Briefing | July 11, 2026 - Critical Zimbra XSS Flaw Executes Code via Email, Progress ShareFile Storage Controllers Under Active Threat, Silver Fox Deploys Rust-Based MODBEACON RAT
Zimbra disclosed a critical stored XSS vulnerability in the Classic Web Client allowing crafted emails to execute arbitrary code in user sessions. Progress Software issued an urgent warning instructing ShareFile customers to immediately shut down Storage Zone Controllers due to a credible external security threat still under investigation. China-linked Silver Fox group is deploying MODBEACON, a Rust-based RAT using gRPC streaming for encrypted C2 communication, targeting cryptocurrency wallet users.
By EACA Summit Content Team

1. Critical Zimbra Flaw Enables Code Execution via Crafted Emails
Zimbra disclosed a critical stored XSS vulnerability in the Classic Web Client that allows specially crafted emails to execute arbitrary code in a user's session. The flaw has no CVE yet but is confirmed by Zimbra's advisory. Organizations using Zimbra should apply patches immediately.
Verified Facts
- Vulnerability is a stored XSS in Zimbra Classic Web Client
- Exploitation requires a crafted email to execute malicious scripts
- No CVE identifier assigned as of reporting
- Zimbra has released updates to address the flaw
Evidence
- Zimbra official advisory referenced in The Hacker News article
- The Hacker News report dated 2026-07-11
Impact
This flaw could allow attackers to compromise email sessions and potentially pivot to internal systems, making it critical for enterprise defenders to prioritize patching.
Confidence Level: High
Sources The Hacker News
2. Progress Software Urges ShareFile Customers to Shut Down Storage Zone Controllers
Progress Software instructed ShareFile customers to immediately shut down Windows servers running Storage Zone Controllers due to a credible external security threat. The company temporarily disabled affected accounts as a precaution while investigating with internal and external security teams. Details of the threat remain under investigation and may evolve.
Verified Facts
- Progress confirmed a credible external security threat to ShareFile Storage Zone Controllers
- Customers told to shut down Windows servers running Storage Zone Controllers
- Affected accounts temporarily disabled out of abundance of caution
- Investigation ongoing with internal and external security teams
Evidence
- Progress Software official statement to The Hacker News
- The Hacker News article dated 2026-07-10
Impact
This incident indicates an active threat targeting file-sharing infrastructure. Defenders should isolate affected systems and monitor for indicators of compromise. Further details are expected as the investigation progresses.
Confidence Level: High
Sources The Hacker News
3. Silver Fox Group Deploys MODBEACON RAT with gRPC C2

The China-linked Silver Fox cybercrime group is using a new Rust-based RAT called MODBEACON, which leverages gRPC streaming for encrypted command-and-control traffic. The group propagates malware via SEO poisoning and counterfeit installers, targeting cryptocurrency wallet private keys and seed phrases.
Verified Facts
- MODBEACON is a Rust-based remote access trojan attributed to Silver Fox
- Uses gRPC streaming for encrypted C2 communication
- Propagation via SEO poisoning and fake installers
- Targets cryptocurrency wallet private keys and seed phrases
Evidence
- QiAnXin threat intelligence report referenced in The Hacker News
- The Hacker News article dated 2026-07-10
Impact
The use of gRPC for C2 makes detection more challenging. Organizations in the cryptocurrency sector should enhance monitoring for unusual gRPC traffic and educate users on SEO poisoning risks.
Confidence Level: High
Sources The Hacker News
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



