CISA says a Russian espionage group stole email and account data from organizations running Zimbra mail servers by abusing a flaw that could trigger just by opening a malicious email. The group, tracked as Laundry Bear or Void Blizzard, exploited Zimbra Collaboration Classic UI XSS flaw CVE-2025-66376 as a zero-day before its November 2025 patch, then used it to exfiltrate 90 days of mail, credentials, Global Address List data, 2FA tokens, and create Zimbra application passcodes for continued access; CISA also says the campaign used adversary-in-the-middle phishing pages impersonating Zimbra logins.
Why it matters: Organizations using Zimbra, especially in government, defense-related, education, energy, media, and NGO sectors, should treat this as urgent because opening a single email could have exposed mailbox contents and long-term account access. Patch Zimbra, hunt for the listed indicators, revoke unauthorized app passcodes, review mailbox access, and reset affected credentials.
info@thehackernews.com (The Hacker News)
2026.07.23
97% relevant
This appears to cover the same underlying event: a Russian espionage group abusing a Zimbra zero-day to steal email and bypass multi-factor authentication by capturing 2FA codes. It likely adds reporting detail and framing from The Hacker News, but the core event, product, actor, and impact align closely with the existing tracked story.
2026.07.23
98% relevant
This article is a direct update on the same joint-government advisory and attack campaign, adding cross-government attribution across the U.S., U.K., Europe, Australia and New Zealand, plus extra sector targeting detail from Unit 42 and Proofpoint, including defense, transportation, finance, and U.S. defense industrial base victims.
Lawrence Abrams
2026.07.23
100% relevant
This article establishes a distinct tracked event: CISA's warning that Laundry Bear/Void Blizzard actively exploited Zimbra CVE-2025-66376 in a zero-click email-theft campaign and paired it with Zimbra-themed AiTM phishing for persistent mailbox access.
2026.07.23
98% relevant
This article is a direct report on the same joint-government alert, adding plain-language detail that the attack triggers on email view with no click, has run since July 2025, and used the Flowerbed collection framework to exfiltrate 90 days of email, passwords, directories, MFA tokens, and app passcodes from targeted Western organizations.
← Back to all stories