⌁ DAY 68

Russian spies exploit Zimbra zero-day for months

3 beadsJul 23 → Jul 29moved 61d ago

The wire

2026-07-29

Russian hackers exploit Exchange zero-day for persistent email access

broke 61d ago · 8 reports · tech · other

Laundry Bear (also known as Void Blizzard), a Russian state-sponsored hacking group, is exploiting an Outlook Web Access zero-day vulnerability in Microsoft Exchange to deliver the OWAReaper backdoor. The campaign targets organizations in Europe and the US for long-term mailbox persistence.

2026-07-23

Russian spies exploit Zimbra zero-day for months

broke 68d ago · 14 reports · other

Russian state-sponsored group 'Laundry Bear' exploited CVE-2025-66376, a zero-click Zimbra vulnerability, to steal emails, passwords, 2FA codes, and directories from US and NATO targets for at least five months. The campaign used phishing emails requiring only message preview to trigger the exploit.

Russian hackers exploit Zimbra zero-click flaw for email theft

broke 68d ago · 8 reports · other · tech

CISA warns that Russian state-sponsored group Laundry Bear (Void Blizzard) is actively exploiting a zero-click vulnerability in Zimbra Collaboration email servers to target Western government and commercial organizations. The exploit is combined with phishing attacks to steal email data.