LIVE · cybersecurity feed
Live wire

zimbra

CVE-2025-66376high

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A sophisticated Russian espionage campaign, attributed to the group TA488 (also known as LAUNDRY BEAR or Void Blizzard), has been actively exploiting a zero-day vulnerability in Zimbra Collaboration's webmail client since at least July 2025. This flaw allowed attackers to steal sensitive data, including emails, contact lists, browser-saved passwords, and two-factor authentication codes, by simply having a user view a specially crafted HTML email. The vulnerability, identified as CVE-2025-66376, was patched by Zimbra in November 2025, but the attackers continued to leverage it for months prior to the fix.