Russian spies exploit Zimbra zero-day for months

Russian state-sponsored group 'Laundry Bear' exploited CVE-2025-66376, a zero-click Zimbra vulnerability, to steal emails, passwords, 2FA codes, and directories from US and NATO targets for at least five months. The campaign used phishing emails requiring only message preview to trigger the exploit.

14 reports · 13 independentother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

🤖 Russian state-sponsored group Laundry Bear exploits Zimbra zero-click 0-day to steal emails, contacts, and 2FA recovery codes from US/Ukraine targets. Opening or previewing the message is enough to

mastodon:infosec-exchangeother67d ago kagi ↗

🤖 Russian state-sponsored group Laundry Bear exploits Zimbra zero-click 0-day to steal emails, contacts, and 2FA recovery codes from US/Ukraine targets. Opening or previewing the message is enough to trigger the exploit. CISA, NSA & FBI issued a joint advisory. 🔗 https://www. bleepingcomputer.com/news/secu rity/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/ # 0day # CyberSec # Z

🔹 darkreading Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only

mastodon:infosec-exchangeother67d ago kagi ↗

🔹 darkreading Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message. 🔗 https://www. darkreading.com/cyberattacks-d ata-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets

🛑 No link. No attachment. Just viewing the email. A Russian state-supported espionage group exploited a Zimbra zero-day for at least 5 months to steal passwords, 2FA recovery codes, organization dire

mastodon:infosec-exchangeother67d ago kagi ↗

🛑 No link. No attachment. Just viewing the email. A Russian state-supported espionage group exploited a Zimbra zero-day for at least 5 months to steal passwords, 2FA recovery codes, organization directories, and 90 days of mail. Read how ZimReaper worked - https:// thehackernews.com/2026/07/russ ian-espionage-group-exploited.html

🏆 New Achievement! Zero-Day, Zero Interaction, Zero Mercy! HEALTH BAR DEPLETED. INTRODUCING: TA488 — Russian state-sponsored, patient as a glacier, and already inside your inbox since July 2025. Five

mastodon:infosec-exchangeother67d ago kagi ↗

🏆 New Achievement! Zero-Day, Zero Interaction, Zero Mercy! HEALTH BAR DEPLETED. INTRODUCING: TA488 — Russian state-sponsored, patient as a glacier, and already inside your inbox since July 2025. Five months as an unknown threat. Five months of your emails, your contacts, your saved browser passwords, and — best of all — your two-factor recovery codes, all vacuumed up just because someone looked a

📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims. Listen/Read: https:// hackread.com

mastodon:mstdn-socialother67d ago kagi ↗

📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims. Listen/Read: https:// hackread.com/russian-hackers-z imbra-0-day-steal-emails-link-clicks/ # CyberSecurity # Zimbra # 0day # Vulnerability # Russia # TA488

Russian hackers steal Western emails with a zero-click Zimbra exploit

stream:bsky-jetstreamother66d ago kagi ↗

A Russian state-supported group called LAUNDRY BEAR is stealing emails from Western governments and defense firms by exploiting a Zimbra webmail flaw that triggers the moment a victim opens a message. A 17-nation advisory warns the campaign is still running. #APT #infosec Nation-State · IntelFusions threat intelligence

A Russian espionage group exploited a Zimbra zero-day for five months, harvesting emails and 2FA codes. The November patch fixes the flaw but won't revoke stolen https:// deafnews.it/en/article/russia

mastodon:infosec-exchangeother65d ago kagi ↗

A Russian espionage group exploited a Zimbra zero-day for five months, harvesting emails and 2FA codes. The November patch fixes the flaw but won't revoke stolen https:// deafnews.it/en/article/russia- exploits-zimbra-zero-day-patching-alone-wont-evict-the-spies

2026-W30 — Weekly Threat Roundup 🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user in

mastodon:infosec-exchangeother65d ago kagi ↗

2026-W30 — Weekly Threat Roundup 🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required. 🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da… https:// threatnoir.com/weekly/2026-w30 # infosec # cybersecurity