logo

Russian hackers exploit unpatched Zimbra servers to steal emails

ID: be58e643-d3ae-5714-b77c-7dfbfbf11a81

STIX ID: report--be58e643-d3ae-5714-b77c-7dfbfbf11a81

Feed Name: Help Net Security

Threat Score
88/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: Sinisa Markovic

...
...

Russian state-backed group Laundry Bear (aka Void Blizzard/TA488) has been exploiting a Zimbra webmail XSS vulnerability (CVE-2025-66376) since July 2025 to steal up to 90 days of email, credentials, directory data, two-factor tokens, and application passcodes across government, defense, energy, education, media, NGOs and tech sectors; stolen data is collected on a Docker-based backend called "Flowerbed," the actors use Mullvad VPN and rotate infrastructure, and agencies recommend patching Zimbra, reviewing IOCs, and revoking unauthorized passcodes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.