LIVE · cybersecurity feed
Live wire
vulnerability

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

Laundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appeared first on CyberScoop.

zeroday.news · 9d ago

A Russian state-sponsored threat group has been exploiting a zero-day vulnerability in Zimbra Collaboration Suite since July 2025, stealing sensitive data from governments and commercial organizations across multiple Western countries. The vulnerability, identified as CVE-2025-66376, was not patched until November 2025, five months after the attacks began. The group, known as Laundry Bear or Void Blizzard, is still actively exploiting unpatched Zimbra instances.

The exploit, which requires no user interaction beyond viewing a malicious email, allows attackers to steal up to 90 days of email content, account passwords, search history, organizational email directories, two-factor authentication tokens, and newly created passwords. This persistent and covert activity, without any known financial extortion, strongly suggests an espionage motivation backed by the Russian government.

The campaign has targeted governments and organizations in the defense, education, energy, law enforcement, media, finance, transportation, and technology sectors. Prior to its use against the U.S. and other NATO allies, the exploit was extensively deployed against Ukrainian targets, indicating a trend among Russian cyber threat groups to use Ukraine as a testing ground for malicious techniques before broader global deployment.

Laundry Bear's year-long campaign demonstrates advanced technical capabilities, including the use of a custom JavaScript payload delivered via phishing emails. The group has also developed a novel data exfiltration and aggregation capability, dubbed "beehive," which officials warn could be adapted to exploit other vulnerabilities.

The medium-severity rating of 6.1 for CVE-2025-66376 highlights the challenges organizations face in prioritizing patching schedules based solely on severity metrics. The Russian state-supported group, active since at least 2024, is believed to manually identify and target victim organizations by scanning for public-facing infrastructure. Once a target is identified, the group likely compiles email addresses for phishing campaigns.

U.S. authorities and cyber officials from 15 other countries, including Australia, Canada, New Zealand, the United Kingdom, Czech Republic, Denmark, Estonia, Finland, France, Italy, Moldova, the Netherlands, Poland, Spain, and Sweden, issued a joint cybersecurity advisory. The advisory includes indicators of compromise and mitigation steps, urging organizations to update their vulnerable software immediately. Specific victims or the total volume of compromised organizations have not been disclosed.

vulnerabilityzero-daypatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.