Mark RadarMARK RADAR
EN
Event File FINTECH Cyberattacks

Russian Hackers Exploit Zimbra Flaw in Global Espionage Campaign

1 reports · First detected 2026-07-24 · Last active 2026-07-24

Zimbra Collaboration Suite is widely used by governments and businesses to manage email, making flaws in the platform valuable for intelligence collection. Laundry Bear, a Russian state-backed group also tracked as Void Blizzard and TA488, has targeted government, defense, transportation and financial organizations in Ukraine, NATO member states, Commonwealth of Independent States countries and Africa. The campaign highlights how compromised webmail can expose sensitive correspondence and undermine account protections.

On July 23, 2026, the NSA, FBI, CISA and allied cyber agencies disclosed that Laundry Bear had exploited CVE-2025-66376 since July 2025. The flaw, patched in November 2025, lets a malicious email inject JavaScript when viewed in vulnerable Zimbra versions. The payload can steal credentials, CSRF tokens, two-factor authentication scratch codes, email archives and up to 90 days of mail and search history. Systems older than ZCS 10.0.18 or 10.1.13 remain exposed unless updated.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)