RUSSIAN state-sponsored hackers, known as 'Laundry Bear,' are exploiting a zero-day vulnerability in the Zimbra Collaboration Suite (ZCS) to target Western governments and organizations. This vulnerability allows phishing attacks that only require the recipient to open a malicious email to be compromised. The threat was outlined in a joint US advisory, revealing that the attacks began in July 2025 and the group has used sophisticated tactics to gather sensitive information.
Zimbra issued a patch in November 2025 for the vulnerability, but signs of exploitation continued as of early 2026. Cybersecurity agencies warned ZCS users to update their systems to prevent further breaches.