Russian hackers exploit unpatched Zimbra servers to steal emails
ID: be58e643-d3ae-5714-b77c-7dfbfbf11a81
STIX ID: report--be58e643-d3ae-5714-b77c-7dfbfbf11a81
Feed Name: Help Net Security
Russian state-backed group Laundry Bear (aka Void Blizzard/TA488) has been exploiting a Zimbra webmail XSS vulnerability (CVE-2025-66376) since July 2025 to steal up to 90 days of email, credentials, directory data, two-factor tokens, and application passcodes across government, defense, energy, education, media, NGOs and tech sectors; stolen data is collected on a Docker-based backend called "Flowerbed," the actors use Mullvad VPN and rotate infrastructure, and agencies recommend patching Zimbra, reviewing IOCs, and revoking unauthorized passcodes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
