logo

Russian hackers exploit Zimbra zero-click flaw for email theft

ID: 4644d532-8816-5acc-9305-88cf945f88e5

STIX ID: report--4644d532-8816-5acc-9305-88cf945f88e5

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Lawrence Abrams

...
...

CISA warns that Russian state-sponsored group Laundry Bear (Void Blizzard) actively exploited a Zimbra Collaboration Classic UI XSS (CVE-2025-66376) as a zero-day to execute JavaScript embedded in emails, automatically exfiltrate the last 90 days of mailbox data, credentials, GAL, and 2FA tokens, and create application passcodes to maintain access. The campaign combined this exploit with AiTM phishing portals impersonating Zimbra, used DNS and HTTPS to transmit stolen data to the group's 'Flowerbed' collection servers, and affected organizations across defense, government, energy, education, and other sectors; CISA released IOCs and mitigation guidance including patching, revoking unauthorized passcodes, and implementing phishing-resistant MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.