Russian hackers exploit Zimbra zero-click flaw for email theft
ID: 4644d532-8816-5acc-9305-88cf945f88e5
STIX ID: report--4644d532-8816-5acc-9305-88cf945f88e5
Feed Name: Bleeping Computer
CISA warns that Russian state-sponsored group Laundry Bear (Void Blizzard) actively exploited a Zimbra Collaboration Classic UI XSS (CVE-2025-66376) as a zero-day to execute JavaScript embedded in emails, automatically exfiltrate the last 90 days of mailbox data, credentials, GAL, and 2FA tokens, and create application passcodes to maintain access. The campaign combined this exploit with AiTM phishing portals impersonating Zimbra, used DNS and HTTPS to transmit stolen data to the group's 'Flowerbed' collection servers, and affected organizations across defense, government, energy, education, and other sectors; CISA released IOCs and mitigation guidance including patching, revoking unauthorized passcodes, and implementing phishing-resistant MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
