Russian Hackers Exploit Zimbra Flaw in Global Espionage Campaign
Zimbra Collaboration Suite is widely used by governments and businesses to manage email, making flaws in the platform valuable for intelligence collection. Laundry Bear, a Russian state-backed group also tracked as Void Blizzard and TA488, has targeted government, defense, transportation and financial organizations in Ukraine, NATO member states, Commonwealth of Independent States countries and Africa. The campaign highlights how compromised webmail can expose sensitive correspondence and undermine account protections.
On July 23, 2026, the NSA, FBI, CISA and allied cyber agencies disclosed that Laundry Bear had exploited CVE-2025-66376 since July 2025. The flaw, patched in November 2025, lets a malicious email inject JavaScript when viewed in vulnerable Zimbra versions. The payload can steal credentials, CSRF tokens, two-factor authentication scratch codes, email archives and up to 90 days of mail and search history. Systems older than ZCS 10.0.18 or 10.1.13 remain exposed unless updated.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.