RUSSIAN state-sponsored hackers are employing a new 'zero-click' attack strategy that targets Western organizations without requiring user interaction. This campaign, identified by multiple western cybersecurity agencies, focuses on exploiting the Zimbra Collaboration Suite (ZCS) software. The hackers, linked to the espionage group Laundry Bear, utilize a zero-day vulnerability (CVE-2025-66376) to access sensitive data such as emails by merely requiring users to view a malicious email.
Affected sectors include defense, government, education, and technology. Organizations are urged to patch vulnerabilities immediately, monitor for suspicious activities, and consider implementing third-party authentication to enhance security. The attackers also exploit AI in their operations, indicating a need for heightened awareness and prompt action in cybersecurity practices.