www.cisa.gov 7/23/2026, 4:00:49 PM · external

LAUNDRY BEAR Uses CVE-2025-66376 to Hack Zimbra via Phishing

Developing story campaign 4 articles tracked
Russian state-backed group exploits Zimbra zero‑click flaw (CVE-2025-66376)
CyberSIXT Evidence Panel Source marked as original reporting
Primary Source media.defense.gov
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
🇷🇺 Void Blizzard

A group of Russian state-supported cyber actors, identified as LAUNDRY BEAR, is conducting phishing campaigns targeting users of the Zimbra Collaboration Suite (ZCS). These activities, ongoing since mid-2025, have exploited a zero-day vulnerability (CVE-2025-66376) to compromise Western government and commercial organizations.

The phishing strategy involves a novel exploit where merely viewing a malicious email can lead to data exfiltration of sensitive information such as the last 90 days of emails and global address lists. CISA and multiple international intelligence agencies have issued warnings urging organizations to patch their systems and adopt security measures to counteract this threat.

The advisory emphasizes the importance of regular software updates, monitoring for suspicious activity, and maintaining security protocols to protect against ongoing and future exploits from this group.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline