Close Menu
NCIJ Network |NCIJ Network |
    What's Hot

    US attacks Iran as Houthis allow Chinese ships to pass: What’s the latest? | US-Israel war on Iran News

    July 24, 2026

    Merz names Nina Warken chancellery chief in Cabinet reshuffle – POLITICO

    July 24, 2026

    Angela Rayner rules out rent controls in England

    July 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • US attacks Iran as Houthis allow Chinese ships to pass: What’s the latest? | US-Israel war on Iran News
    • Merz names Nina Warken chancellery chief in Cabinet reshuffle – POLITICO
    • Angela Rayner rules out rent controls in England
    • ECB Consumer Expectations Survey results – June 2026
    • How AI guardrails are impeding the work of offensive cybersecurity researchers
    • OpenAI Presence: enterprise AI agents, engineers included
    • Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
    • BitMEX Users Seek 623 BTC in Liquidation Fraud Suit
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network |NCIJ Network |
    Friday, July 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network |NCIJ Network |
    Home»Cybersecurity

    Russian Hackers Exploit Zimbra 0-Day Against US, Ukraine Targets

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 24, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Russian state-backed threat actors are compromising networks of Western governments and enterprises through the Zimbra Collaboration Suite (ZCS), according to intelligence and cybersecurity agencies in more than a dozen countries.

    In a joint advisory Thursday, the US government and several allied nations warned that an advanced persistent threat (APT) dubbed “Laundry Bear” has been targeting ZCS customers since July 2025. Laundry Bear actors used a zero-day vulnerability in ZCS, tracked as CVE-2025-66376, in a phishing campaign that featured what experts describe as a “half-click exploit” to breach Zimbra webmail servers.

    “Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, Laundry Bear’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service,” the agencies said in the advisory.

    Related:Brazilian Banking Trojan Actively Spreading in Portugal

    The campaign is designed “almost certainly to gather sensitive information for the Russian Federation,” according the advisory. The Laundry Bear attacks mark yet another threat from Russian APTs against US organizations.

    Zimbra Zero-Day Activity

    Zimbra patched CVE-2025-66376 in November 2025 with the release of version 10.1.13, though the company did not disclose the flaw until weeks later. The initial release notes for v10.1.13 merely described the flaw as “a stored XSS vulnerability in the Classic UI where attackers could abuse CSS @import directives in email HTML,” with no CVE at the time.

    The National Institute of Standards and Technology (NIST) and Mitre did not publish entries for the Zimbra flaw until early January. Dark Reading contacted Zimbra and parent company Synacor for comment on the apparent delayed disclosure for CVE-2025-66376, but neither company responded at press time.

    In a March 17 blog post, cybersecurity firm Seqrite reported that Russian threat actors had exploited CVE-2025-66376 in the compromise of a Ukrainian government agency. At the time, Seqrite attributed the activity, which it called “Operation GhostMail,” to APT28, also known as Fancy Bear.

    The following day, the US Cybersecurity and Infrastructure Security Agency (CISA) added the high-severity vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on March 18. Mitre also gave the vulnerability a 7.2 CVSS score.

    However, intelligence and cybersecurity agencies from 15 different countries revealed the exploitation activity was far more extensive and dated back to at least July 2025. They also tied the phishing campaign to a different Russian “Bear.”

    Related:Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain

    Laundry Bear’s ‘Half-Click’ Zimbra Exploit

    According to the joint advisory, the Netherlands General Intelligence and Security Service (AIVD) first identified Laundry Bear in May as a new Russian state-sponsored APT adjacent to other more well-known groups. Laundry Bear, the authoring agencies said, had previously relied on unsophisticated tactics such as password spraying and conventional phishing attacks until last year, when actors began using a “novel exploit” for CVE-2025-66376 that no longer required targeted victims to click on a link or open a malicious email attachment.

    In a blog post on Thursday, Proofpoint, which contributed to the government investigations into Laundry Bear, explained that the Zimbra vulnerability allowed the threat actors to craft “half-click” phishing emails that only needed a victim to open or preview the message.

    “If the email is opened in Zimbra Webmail, regardless of the user’s browser, a vulnerable Zimbra webmail client will mishandle the HTML from the message and run arbitrary JavaScript,” Proofpoint researchers wrote, adding that the exploit then collects the victim’s messages for the past 90 days and exfiltrates the data to a command-and-control (C2) server.

    Related:Ransomware Is Accelerating, but It’s Not Because of AI

    Proofpoint researchers noted that Laundry Bear, which they track as TA488, targeted not only Ukrainian government entities but US government agencies, defense companies, and scientific organizations. They also noted that the threat actors used the exploit for “at least five months during 2025” and appeared to cease operations in February following Seqrite’s detection.

    While Laundry Bear’s Zimbra campaign may have ended, the threat to Zimbra customers remains. Greg Lesnewich, principal threat research engineer at Proofpoint, tells Dark Reading that the company has observed “other unclustered activity sets” exploiting the flaw in unpatched webmail servers.

    Proofpoint researchers noted that the CVE-2025-66376 exploit was likely gifted to Laundry Bear by Russian intelligence agencies rather than being developed internally. Additionally, the researchers warned that it’s possible the APT group may be using large language models to “develop a bypass for Zimbra’s patch to continue targeting Zimbra servers.”

    Lesnewich says that while Proofpoint did not observe any technical evidence that the exploit was generated by AI, “it is plausible, as LLMs would likely be proficient in identifying such XSS flaws in webmail software.”

    The joint advisory urged ZCS customers to immediately update their software to a fixed version or, if patching is not possible, switch to alternative webmail clients. The agencies said system administrators should closely monitor any Internet-connected ZCS instances or email systems for signs of compromise.

    0Day exploit hackers Russian targets Ukraine Zimbra
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

    Hackers abuse Notepad++ plugins to stealthily install malware

    Image shows smoke rising from Russian warehouse after Ukrainian drone strike

    Ukraine beheads its military as its performance begins to soar | Russia-Ukraine war News

    Russian hackers exploit Zimbra zero-click flaw for email theft

    Chick-fil-A Accounts Get Fried in Credential Stuffing Attack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    US attacks Iran as Houthis allow Chinese ships to pass: What’s the latest? | US-Israel war on Iran News

    July 24, 2026

    Merz names Nina Warken chancellery chief in Cabinet reshuffle – POLITICO

    July 24, 2026

    Angela Rayner rules out rent controls in England

    July 24, 2026

    ECB Consumer Expectations Survey results – June 2026

    July 24, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    US attacks Iran as Houthis allow Chinese ships to pass: What’s the latest? | US-Israel war on Iran News

    July 24, 2026

    Merz names Nina Warken chancellery chief in Cabinet reshuffle – POLITICO

    July 24, 2026

    Angela Rayner rules out rent controls in England

    July 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.