Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
ID: 68344970-b9b9-59e5-9eeb-c71dbed140e9
STIX ID: report--68344970-b9b9-59e5-9eeb-c71dbed140e9
Feed Name: CosmicBytez Labs
Laundry Bear, a Russian state-sponsored APT, is actively exploiting a zero-day in Zimbra Collaboration via a "half-click" phishing technique that triggers payloads when an email is opened or previewed; targets include US and Ukrainian government entities. Organizations using Zimbra are urged to treat this as critical: audit and patch Zimbra, review logs, restrict external webmail access where possible, enable enhanced monitoring, and report suspicious activity to national cybersecurity authorities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
