Russian APT 'Laundry Bear' Exploited Zimbra Zero-Day with Half-Click Email Attack
ID: 02a1eb95-1218-5587-b702-74acd81674e7
STIX ID: report--02a1eb95-1218-5587-b702-74acd81674e7
Feed Name: CosmicBytez Labs
**Executive Summary:** A Russia-backed APT known as Laundry Bear exploited a stored XSS zero-day (CVE-2025-66376) in Zimbra's Classic UI using a 'half-click' HTML email technique to execute JavaScript (ZimReaper/Ulej), exfiltrate up to 90 days of email, credentials, GAL entries and 2FA/TOTP tokens, mint application-specific 'ZimbraWeb' passwords to bypass MFA and obtain persistent IMAP/SMTP access across government, defense, energy, and NGO targets; organizations must patch to Zimbra 10.1.13 and revoke all application-specific passwords and investigate potential compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
