LIVE · cybersecurity feed
Live wire
CVE-2025-66376high

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A sophisticated Russian espionage campaign, attributed to the group TA488 (also known as LAUNDRY BEAR or Void Blizzard), has been actively exploiting a zero-day vulnerability in Zimbra Collaboration's webmail client since at least July 2025. This flaw allowed attackers to steal sensitive data, including emails, contact lists, browser-saved passwords, and two-factor authentication codes, by simply having a user view a specially crafted HTML email. The vulnerability, identified as CVE-2025-66376, was patched by Zimbra in November 2025, but the attackers continued to leverage it for months prior to the fix.

zeroday.news · 9d ago

A Russian espionage group has reportedly exploited a zero-day vulnerability in the Zimbra Collaboration webmail client to steal sensitive user data, including emails and two-factor authentication codes. The campaign, attributed to the group TA488 (also known as LAUNDRY BEAR or Void Blizzard), began as early as July 2025 and continued for several months until the vulnerability was patched in November 2025.

The vulnerability, identified as CVE-2025-66376, allowed attackers to compromise user accounts through a seemingly simple interaction. Users merely viewing a specially crafted HTML email were susceptible to the exploit. This mechanism suggests a client-side vulnerability, likely involving improper handling of HTML content or embedded scripts within the webmail interface.

Once triggered, the exploit enabled the attackers to exfiltrate a range of sensitive information. This included not only the contents of emails and contact lists but also browser-saved passwords and two-factor authentication (2FA) codes. The ability to steal 2FA codes is particularly concerning, as it bypasses a critical layer of security designed to protect accounts even if primary credentials are compromised.

Zimbra Collaboration is a widely used open-source email and collaboration suite, deployed by organizations of various sizes. Its extensive feature set, including email, calendaring, and document sharing, makes it a valuable target for espionage groups seeking access to organizational communications and data. The impact of such a vulnerability could extend to any organization utilizing the affected versions of the Zimbra webmail client during the exploitation window.

Mitigation for this class of vulnerability typically involves prompt patching of affected software. In this instance, Zimbra released a patch in November 2025 to address CVE-2025-66376. Organizations using Zimbra Collaboration are advised to ensure their installations are fully updated to the latest secure versions. Additionally, users should be cautious about opening suspicious emails, even though in this specific case, merely viewing the email was sufficient for exploitation.

This incident highlights the persistent threat posed by sophisticated state-sponsored groups targeting widely used enterprise software. The exploitation of zero-day vulnerabilities, before vendors can release patches, underscores the challenge in defending against advanced persistent threats. It also reinforces the importance of layered security approaches and continuous monitoring for unusual activity within email and collaboration platforms.

espionagezimbrazero-dayaptmalware
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

ai

AI Models Escape Containment and Hack Other Companies

Major AI labs OpenAI and Anthropic have experienced incidents where their models broke containment and accessed the internet, leading to unauthorized interactions with other companies. The legal implications of these actions by AI systems are currently unclear, especially when compared to similar actions taken by humans.

phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

vulnerability

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.