Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

CyberScoop+1CyberScoop+1BleepingComputer+1U.S. and allied cybersecurity agencies on Thursday issued a joint advisory warning that the Russian state-backed threat group Laundry Bear has been exploiting a vulnerability in Zimbra Collaboration Suite to steal sensitive email data from Western governments and commercial organizations since July 2025.Facebookapp+1
The advisory, co-authored by the NSA, CISA, FBI, and cyber agencies from 15 other countries including the United Kingdom, Australia, Canada, and the Netherlands, describes a campaign that requires no user interaction beyond viewing a malicious email.CyberScoop+1
Laundry Bear, also tracked as Void Blizzard, exploits CVE-2025-66376, a stored cross-site scripting flaw in Zimbra's Classic UI that allows malicious JavaScript embedded in HTML emails to execute automatically when a victim views the message. The vulnerability, which affects Zimbra Collaboration Suite versions 10.0.x before 10.0.18 and 10.1.x before 10.1.13, was not patched until November 2025 — five months after exploitation began.SentinelOne+2
The exploit enables attackers to steal up to 90 days of email, account passwords, search history, the organization's email directory, and two-factor authentication tokens. Officials described a custom data exfiltration and aggregation capability dubbed "beehive" that could potentially be adapted to exploit other vulnerabilities.BleepingComputer+1
Laundry Bear has been active since at least 2024 and was first publicly identified by Dutch intelligence services and Microsoft in May 2025. The group has compromised targets across the defense, education, energy, law enforcement, media, finance, transportation, and technology sectors.Theregister+2
Officials noted that the campaign first targeted Ukrainian organizations before expanding to U.S. and NATO allies, a pattern increasingly common among Russian cyber threat groups. The group is still actively exploiting unpatched Zimbra instances, authorities said.CyberScoop+1
Agencies urged organizations to immediately update Zimbra to patched versions, review indicators of compromise shared in the advisory, and monitor for suspicious authentication activity. Organizations unable to patch should avoid using the Classic webmail client and consider alternative email clients until systems are updated.Facebookapp+1
"The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group's involvement in espionage activities with Russian government backing," the advisory states.CyberScoop