logo

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

ID: a8043955-83e2-5933-b7eb-b07ad03a36ea

STIX ID: report--a8043955-83e2-5933-b7eb-b07ad03a36ea

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Matt Kapko

...
...

A joint advisory warns that the Russian state‑sponsored group Laundry Bear (Void Blizzard) exploited a zero‑day in Zimbra Collaboration Suite (CVE-2025-66376) in an active espionage campaign from July 2025, stealing up to 90 days of email, passwords, search history, directory data and 2FA tokens; the vulnerability was not patched until November 2025 and affected governments and organizations across multiple critical sectors, with IOCs and mitigations released by multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.