securityaffairs.com 7/24/2026, 8:50:21 AM · external

US agencies warn Laundry Bear exploits CVE-2025-66376 in Zimbra

US agencies warn Laundry Bear exploits CVE-2025-66376 in Zimbra
Developing story campaign 5 articles tracked
Russian state-backed group exploits Zimbra zero‑click flaw (CVE-2025-66376)
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
🇷🇺 Void Blizzard

US agencies including CISA, NSA, and FBI have issued a warning about the Russian-linked APT group Laundry Bear, which is exploiting a patched vulnerability (CVE-2025-66376) in Zimbra servers to steal email accounts from unpatched systems. This zero-click exploit allows remote execution of malicious JavaScript through viewed emails, bypassing traditional phishing techniques. Laundry Bear's attacks utilize previous compromised accounts for credibility, embedding an encrypted payload in emails.

The malware extracts sensitive information, enables IMAP access, and exfiltrates data through secure channels. CISA recommends updating Zimbra, monitoring for anomalies, and employing multi-factor authentication to protect against these unauthorized accesses.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline