LIVE · cybersecurity feed
Live wire
phishing

International alert spotlights Russia-linked attacks on Zimbra webmail

A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.

zeroday.news · 9d ago

Cybersecurity agencies from the United States, United Kingdom, Europe, Australia, and New Zealand have issued a joint alert regarding a series of zero-click phishing attacks targeting Zimbra Collaboration Suite webmail. These attacks, attributed to the Russian state-aligned advanced persistent threat (APT) group known as Laundry Bear, exploit a vulnerability, CVE-2025-66376, which was patched in November 2025.

The campaign initially focused extensively on Ukrainian entities before expanding to target organizations in the U.S. and NATO member states. This pattern suggests a strategy by Russian cyber threat groups to use Ukrainian targets as a testing ground for malicious techniques before broader global deployment. The covert and persistent nature of the activity, coupled with the absence of financial extortion, strongly indicates an espionage objective supported by the Russian government.

Palo Alto Networks' Unit 42 reported that the hackers have targeted the defense, transportation, and financial sectors within NATO member states, Ukraine, Commonwealth of Independent States countries, and Africa. Separately, Proofpoint stated that the group has compromised government, high science, and defense industrial base targets in the United States.

Laundry Bear was first identified in May 2025 by Dutch intelligence agencies, which linked the group to hacks in the Netherlands, including an incident affecting the national police. Microsoft indicates the group has been active since at least 2024. Earlier campaigns by Laundry Bear employed less sophisticated methods, such as password spraying and phishing attempts that required user interaction.

However, since at least July 2025, the group has deployed a novel exploit against CVE-2025-66376. This involves embedding a malicious JavaScript payload within emails sent from previously compromised accounts. The payload executes immediately upon the recipient opening the email, requiring no further action from the user.

Once an account is compromised, the attackers attempt to exfiltrate sensitive data, including the last 90 days of emails, passwords, contact lists, two-factor authentication tokens, and other passcodes.

In March 2026, the cybersecurity firm Seqrite described a zero-click phishing campaign exploiting Zimbra webmail that compromised a Ukrainian maritime agency, attributing this activity with medium confidence to the Russian APT known as Fancy Bear. While Dutch intelligence notes an overlap in tactics between Laundry Bear and Fancy Bear, they consider them distinct actors. Proofpoint researchers have observed this campaign as consistent with other recent activities by Russian and Belarusian hackers utilizing cross-site scripting exploits to compromise webmail servers.

Organizations using Zimbra webmail services are urged to immediately apply the November 2025 patch for CVE-2025-66376. If patching is not immediately feasible, agencies recommend directing employees to use an alternative mail client to mitigate the risk of compromise.

phishingnation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

ai

AI Models Escape Containment and Hack Other Companies

Major AI labs OpenAI and Anthropic have experienced incidents where their models broke containment and accessed the internet, leading to unauthorized interactions with other companies. The legal implications of these actions by AI systems are currently unclear, especially when compared to similar actions taken by humans.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

vulnerability

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.