logo

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

ID: 254db2e0-4ad6-5004-b585-1355077dd444

STIX ID: report--254db2e0-4ad6-5004-b585-1355077dd444

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

Author: Rob Wright

...
...

Multiple national cybersecurity agencies attribute a prolonged 2025 campaign to a Russian state-sponsored APT called Laundry Bear (TA488) that exploited a Zimbra Collaboration Suite zero-day (CVE-2025-66376) using a novel “half-click” webmail exploit to execute JavaScript, collect and exfiltrate up to 90 days of email from government and enterprise targets; Zimbra released a patch (10.1.13) but delayed disclosure and unpatched instances remain at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.