Zero-Click Attacks and Critical Infrastructure Threats: July 23rd Update

by The Creator | Jul 23, 2026

A zero-click email attack targeting Zimbra servers allows Russian state-backed hackers to steal data without requiring employees to click links or open attachments, and CISA has issued urgent patching orders for all organizations using affected versions.

Russian state-backed hackers are exploiting a zero-click vulnerability in Zimbra email servers that doesn't require users to click links or open attachments. CISA has issued urgent warnings for organizations to patch immediately. Meanwhile, Iranian hackers are intensifying attacks on U.S. critical infrastructure, specifically targeting water and energy providers' industrial control systems from major vendors like Rockwell, Schneider Electric, and Siemens. These attacks can disable safety alarms without operator notification. In consumer news, Chick-fil-A disclosed a credential stuffing attack on its loyalty program. Security experts remind everyone that with data breaches now commonplace, freezing credit and using multi-factor authentication are essential protections.

How does a zero-click email attack bypass your team's defenses?

Zero-click attacks work differently from phishing because they don't depend on user error. The vulnerability in Zimbra email servers (CVE details tracked by CISA) activates when the malicious email arrives in an inbox, period. For manufacturers and professional services firms that rely on email for client communications and operational data, this attack vector bypasses training entirely. The immediate action: if your organization uses Zimbra, contact your IT provider today to confirm patch status and verify no compromise occurred. CISA has published specific remediation guidance. Parallel threat: Iranian-backed actors are also targeting industrial control systems from Rockwell and Siemens, disabling safety alarms silently, so if your facility uses legacy systems, audit access logs now.

Key takeaways

  • If you use Zimbra email, request an immediate patch status from your IT provider; exploitation is active.
  • Zero-click attacks bypass user training, so assume your team cannot stop this one through behavior alone.
  • Check your email access logs for suspicious logins from July 23rd onward, especially near your finance or operations accounts.
  • If you operate industrial equipment from Rockwell or Schneider Electric, review your OT network isolation and alarm system logs for tampering.

Frequently asked questions

Do I need to do anything if my team didn't click anything suspicious?

Yes. Zero-click attacks don't require clicking, so user behavior is irrelevant. If your Zimbra server is unpatched, you may already be compromised. Contact your IT provider for a vulnerability scan and patch deployment immediately.

What should I tell my IT provider to check?

Ask them to verify your Zimbra version against CISA's advisory, confirm patches are applied, and run email logs for unauthorized access or forwarding rules created between July 20-23. Request a brief report in writing.

Is this the same as the Chick-fil-A breach mentioned?

No. Chick-fil-A's breach was credential stuffing (reused passwords), a different attack. Both are serious, but they require different responses: update your Zimbra patch now, and monitor your company accounts for unauthorized access using multi-factor authentication.

Do I have time to patch, or is this an emergency?

Treat it as urgent. Active exploitation has been confirmed by CISA and Russia-linked groups. Patches are available, and most can deploy within 24-48 hours with your IT partner. Delaying increases your exposure window significantly.

Sources

Keep reading