THE UK's National Cyber Security Centre (NCSC) has warned of a new zero-click phishing campaign conducted by the Russian state-supported hacking group, LAUNDRY BEAR. This group has developed a technique, referred to as "beehive" or "Ulej," to target organizations using Zimbra Collaboration Suite (ZCS) software, stealing sensitive email data without user interaction. The campaign has successfully targeted various sectors in the United States, including defense and education.
Organizations are advised to patch vulnerabilities in ZCS and improve monitoring capabilities, as this method may be adapted to exploit other email systems. The advisory was issued in collaboration with cyber agencies from 15 countries, highlighting the necessity for greater cyber resilience and proactive security measures.