Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
ID: 254db2e0-4ad6-5004-b585-1355077dd444
STIX ID: report--254db2e0-4ad6-5004-b585-1355077dd444
Feed Name: Dark Reading
Threat Score
Multiple national cybersecurity agencies attribute a prolonged 2025 campaign to a Russian state-sponsored APT called Laundry Bear (TA488) that exploited a Zimbra Collaboration Suite zero-day (CVE-2025-66376) using a novel “half-click” webmail exploit to execute JavaScript, collect and exfiltrate up to 90 days of email from government and enterprise targets; Zimbra released a patch (10.1.13) but delayed disclosure and unpatched instances remain at risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
