logo

Russian hackers can steal emails without a click

ID: 2bd20ea2-cdb7-5db5-bfd1-d9af4714a1f0

STIX ID: report--2bd20ea2-cdb7-5db5-bfd1-d9af4714a1f0

Feed Name: Proofpoint Blog

Threat Score
85/100

Date Published: 2026-08-07

Date Updated: 2026-08-15

...
...

CISA, NSA, FBI and allied agencies warn that Russian state-sponsored group Laundry Bear (Void Blizzard) exploited a Zimbra Classic UI XSS (CVE-2025-66376) as a zero-click/half-click vector to steal up to 90 days of email, passwords, MFA/session tokens, and to create persistent Zimbra application passcodes; the group used a collection framework called Flowerbed (DNS and HTTPS exfiltration) and phishing sites impersonating Zimbra infrastructure, and has targeted governments, defense, education, energy and related sectors — organizations must patch Zimbra, search for listed IOCs/domains, revoke unknown app passcodes and investigate mailbox and network logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.