logo

Response to CISA Advisory (AA26-204A): Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

ID: d4c26edd-5df3-5a80-9e55-10979d0a5d82

STIX ID: report--d4c26edd-5df3-5a80-9e55-10979d0a5d82

Feed Name: Security Boulevard

Threat Score
90/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

Author: Francis Guibernau

...
...

CISA and partners published a joint advisory describing Laundry Bear (a Russian state‑supported actor) exploiting a Zimbra zero‑day (CVE-2025-66376) since at least July 2025 to silently exfiltrate up to 90 days of email, GAL entries, and other sensitive data; AttackIQ provides emulation scenarios and CISA mitigation guidance emphasizing immediate patching, monitoring of network/exfiltration indicators, and authentication hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.