Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
ID: a8043955-83e2-5933-b7eb-b07ad03a36ea
STIX ID: report--a8043955-83e2-5933-b7eb-b07ad03a36ea
Feed Name: CyberScoop
Threat Score
A joint advisory warns that the Russian state‑sponsored group Laundry Bear (Void Blizzard) exploited a zero‑day in Zimbra Collaboration Suite (CVE-2025-66376) in an active espionage campaign from July 2025, stealing up to 90 days of email, passwords, search history, directory data and 2FA tokens; the vulnerability was not patched until November 2025 and affected governments and organizations across multiple critical sectors, with IOCs and mitigations released by multiple countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
