A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.

Cybersecurity agencies from the United States, United Kingdom, Europe, Australia, and New Zealand have issued a joint alert regarding a series of zero-click phishing attacks targeting Zimbra Collaboration Suite webmail. These attacks, attributed to the Russian state-aligned advanced persistent threat (APT) group known as Laundry Bear, exploit a vulnerability, CVE-2025-66376, which was patched in November 2025.
The campaign initially focused extensively on Ukrainian entities before expanding to target organizations in the U.S. and NATO member states. This pattern suggests a strategy by Russian cyber threat groups to use Ukrainian targets as a testing ground for malicious techniques before broader global deployment. The covert and persistent nature of the activity, coupled with the absence of financial extortion, strongly indicates an espionage objective supported by the Russian government.
Palo Alto Networks' Unit 42 reported that the hackers have targeted the defense, transportation, and financial sectors within NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Separately, Proofpoint stated that the group has compromised government, high science, and defense industrial base targets in the United States.
Laundry Bear was first identified in May 2025 by Dutch intelligence agencies, which linked the group to hacks in the Netherlands, including an incident affecting the national police. Microsoft indicates the group has been active since at least 2024. Earlier campaigns by Laundry Bear employed less sophisticated methods, such as password spraying and phishing attempts that required user interaction.
However, since at least July 2025, the group has deployed a novel exploit against CVE-2025-66376. This involves embedding a malicious JavaScript payload within emails sent from previously compromised accounts. The payload executes immediately upon the recipient opening the email, requiring no further action from the user.
Once an account is compromised, the attackers attempt to exfiltrate sensitive data, including the last 90 days of emails, passwords, contact lists, two-factor authentication tokens, and other passcodes.
In March 2026, the cybersecurity firm Seqrite described a zero-click phishing campaign exploiting Zimbra webmail that compromised a Ukrainian maritime agency, attributing this activity with medium confidence to the Russian APT known as Fancy Bear. While Dutch intelligence notes an overlap in tactics between Laundry Bear and Fancy Bear, they consider them distinct actors. Proofpoint researchers have observed this campaign as consistent with other recent activities by Russian and Belarusian hackers utilizing cross-site scripting exploits to compromise webmail servers.
Organizations using Zimbra webmail services are urged to immediately apply the November 2025 patch for CVE-2025-66376. If patching is not immediately feasible, agencies recommend directing employees to use an alternative mail client to mitigate the risk of compromise.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed