Russian hackers exploit Zimbra zero-click flaw for email theft

CISA warns that Russian state-sponsored group Laundry Bear (Void Blizzard) is actively exploiting a zero-click vulnerability in Zimbra Collaboration email servers to target Western government and commercial organizations. The exploit is combined with phishing attacks to steal email data.

8 reports · 7 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Agencies warn Russian hackers are exploiting Zimbra zero-click flaw

kite:cybersecurityother68d ago kagi ↗

U.S. and allied cyber agencies warned that Russian state-backed actors tracked as LAUNDRY BEAR have targeted and compromised Western government and commercial organizations through Zimbra Collaboration Suite since at least July 2025 [cisa.gov#1][cyberscoop.com#1][thehackernews.com#1][therecord.media#1]. The campaign exploits CVE-2025-66376, a Zimbra flaw that was a zero-day when first used and tha

Russian hackers exploit Zimbra zero-click flaw for email theft

rss:bleepingcomputertech68d ago kagi ↗

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]

🤖 CISA warns Russian APT group Laundry Bear (Void Blizzard) is exploiting a zero-click Zimbra Collaboration vulnerability in active attacks. The flaw, combined with phishing, allows email theft from

mastodon:infosec-exchangeother68d ago kagi ↗

🤖 CISA warns Russian APT group Laundry Bear (Void Blizzard) is exploiting a zero-click Zimbra Collaboration vulnerability in active attacks. The flaw, combined with phishing, allows email theft from unpatched servers. 🔗 https://www. bleepingcomputer.com/news/secu rity/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/ # CVE # Zimbra # CyberSec # APT # EmailSecurity

Russian hackers target Zimbra servers via patched flaw CISA warns of email theft by state-backed group using phishing and exploits https:// hostingpaper.com/article/russi an-hackers-exploit-patched-zi

mastodon:mstdn-socialother68d ago kagi ↗

Russian hackers target Zimbra servers via patched flaw CISA warns of email theft by state-backed group using phishing and exploits https:// hostingpaper.com/article/russi an-hackers-exploit-patched-zimbra-flaw-in-email-theft # Security # IncidentsBreaches

Western agencies warn Russian hackers are exploiting Zimbra email

kite:cybersecurityother67d ago kagi ↗

Cybersecurity and intelligence agencies in the United States, the United Kingdom, the Netherlands, Finland and other Western partner countries warned on July 24 that Russian state-backed group Laundry Bear has targeted organizations running Zimbra Collaboration Suite since at least July 2025 [helpnetsecurity.com#1][risky.biz#1][finchannel.com#1][cna.com.tw#1][maaseuduntulevaisuus.fi#1]. The campai

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microso

mastodon:infosec-exchangeother67d ago kagi ↗

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. https://www. bleepingcomputer.com/news/micr osoft/microsoft-blames-massive-microsoft-365-outage-on-maintenance-bug/