www.infosecurity-magazine.com 7/23/2026, 3:59:48 PM · external

Russian zero-click attack exploits Zimbra flaw CVE-2025-66376

Russian zero-click attack exploits Zimbra flaw CVE-2025-66376
Developing story campaign 4 articles tracked
Russian state-backed group exploits Zimbra zero‑click flaw (CVE-2025-66376)
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
🇷🇺 Void Blizzard

RUSSIAN state-sponsored hackers are employing a new 'zero-click' attack strategy that targets Western organizations without requiring user interaction. This campaign, identified by multiple western cybersecurity agencies, focuses on exploiting the Zimbra Collaboration Suite (ZCS) software. The hackers, linked to the espionage group Laundry Bear, utilize a zero-day vulnerability (CVE-2025-66376) to access sensitive data such as emails by merely requiring users to view a malicious email.

Affected sectors include defense, government, education, and technology. Organizations are urged to patch vulnerabilities immediately, monitor for suspicious activities, and consider implementing third-party authentication to enhance security. The attackers also exploit AI in their operations, indicating a need for heightened awareness and prompt action in cybersecurity practices.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline