www.ncsc.gov.uk 7/23/2026, 3:59:49 PM · external

UK NCSC alerts on Laundry Bear zero click attack on Zimbra email

UK NCSC alerts on Laundry Bear zero click attack on Zimbra email
Developing story campaign 4 articles tracked
Russian state-backed group exploits Zimbra zero‑click flaw (CVE-2025-66376)
CyberSIXT Evidence Panel
Primary Source media.defense.gov
Threat Actor
🇷🇺 Void Blizzard

THE UK's National Cyber Security Centre (NCSC) has warned of a new zero-click phishing campaign conducted by the Russian state-supported hacking group, LAUNDRY BEAR. This group has developed a technique, referred to as "beehive" or "Ulej," to target organizations using Zimbra Collaboration Suite (ZCS) software, stealing sensitive email data without user interaction. The campaign has successfully targeted various sectors in the United States, including defense and education.

Organizations are advised to patch vulnerabilities in ZCS and improve monitoring capabilities, as this method may be adapted to exploit other email systems. The advisory was issued in collaboration with cyber agencies from 15 countries, highlighting the necessity for greater cyber resilience and proactive security measures.

View Primary Source Via www.ncsc.gov.uk

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline