All incidents

Russian state-backed group exploits Zimbra zero‑click flaw (CVE-2025-66376)

campaignopenJul 23, 2026 — Jul 23, 2026
LAUNDRY BEAR Uses CVE-2025-66376 to Hack Zimbra via Phishing

LAUNDRY BEAR, a Russian state‑backed espionage group, has been observed exploiting a zero‑day flaw in Zimbra Collaboration Suite to steal email data through specially crafted phishing messages that require no interaction from the recipient according to a joint advisory. The activity, tracked since mid‑2025, has hit government agencies, defence contractors and educational institutions across the West, prompting urgent alerts from CISA and the UK NCSC.

The vulnerability, designated CVE-2025-66376, carries a CVSS score of 7.2 and has been added to the Known Exploited Vulnerabilities catalogue as noted by CISA. The flaw resides in the webmail component and can be triggered when a user merely views a malicious HTML email, allowing embedded JavaScript to run and exfiltrate the last ninety days of correspondence along with the global address list.

Although the vendor has not been publicly named, the affected product is Zimbra Collaboration Suite and a security update is now available from the supplier the UK NCSC advises. Applying the patch closes the vector that attackers use to inject malicious script into outgoing messages.

Intelligence linking the campaign to the threat cluster known as Void Blizzard shows that the actors have used a technique nicknamed beehive or Ulej to deliver the payload as reported by Infosecurity Security. Targets have included departments of defence, university research centres and technology firms in the United States and Europe, with the espionage effort focusing on harvesting strategic correspondence and address books.

Organisations should apply the latest Zimbra patch without delay and verify that all front‑end servers are running the updated version. Email gateways ought to be configured to strip or sanitise HTML tags and to block messages that contain suspicious script elements. Security teams must enable detailed mailbox logging, watch for unusual IMAP or SMTP authentication spikes and review access to the global address list for abnormal queries as highlighted in Unit 42 analysis.

Implementing multi‑factor authentication for webmail access reduces the value of harvested credentials. Conduct regular phishing simulations that test resistance to zero‑click lures and update intrusion‑detection rules to flag outbound data transfers to unfamiliar domains. Sharing indicators of compromise with trusted partners and participating in the joint advisory network improves collective defence against this evolving threat.

Administrators should also enforce DMARC, DKIM and SPF policies to reduce spoofed mail that could carry the exploit payload. Limiting external URL clicks within webmail and disabling automatic image loading further lowers the chance of accidental execution. Finally, regular threat‑hunting exercises that search for atypical mailbox export commands or unknown scheduled tasks help catch intrusions before data leaves the network.

Intelligence briefing updated Jul 23, 2026

CVE-2025-66376 7.2 KEV Void Blizzard
Root sourcemedia.defense.gov
Timeline Coverage

Swipe to explore timeline