International alert spotlights Russia-linked attacks on Zimbra webmail
ID: fe67f71f-f024-5e6f-9f9d-894b87fa357c
STIX ID: report--fe67f71f-f024-5e6f-9f9d-894b87fa357c
Feed Name: The Record from Recorded Future News
Russian state-aligned APT 'Laundry Bear' conducted a zero-click phishing campaign exploiting a Zimbra webmail vulnerability (CVE-2025-66376) to immediately execute malicious JavaScript from compromised emails and exfiltrate sensitive data (recent emails, passwords, contact lists, 2FA tokens) from government, defense, transportation and financial targets across Ukraine, NATO countries and others; agencies and vendors urge immediate patching or use of alternative mail clients.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
