Russian state-sponsored group 'Laundry Bear' exploited CVE-2025-66376, a zero-click Zimbra vulnerability, to steal emails, passwords, 2FA codes, and directories from US and NATO targets for at least five months. The campaign used phishing emails requiring only message preview to trigger the exploit.
14 reports · 13 independentother
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
🤖 Russian state-sponsored group Laundry Bear exploits Zimbra zero-click 0-day to steal emails, contacts, and 2FA recovery codes from US/Ukraine targets. Opening or previewing the message is enough to trigger the exploit. CISA, NSA & FBI issued a joint advisory. 🔗 https://www. bleepingcomputer.com/news/secu rity/russian-hackers-exploit-zimbra-zero-click-flaw-for-email-theft/ # 0day # CyberSec # Z
🔹 darkreading Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message. 🔗 https://www. darkreading.com/cyberattacks-d ata-breaches/russian-hackers-zimbra-zero-day-us-ukraine-targets
Russian hackers quietly tested the zero-click tactic in Ukraine before targeting NATO member organizations, CISA says. cybernews.com/security/rus... Russian spies are exploiting an unpatched Zimbra zero-day requiring no clicks to steal emails from Western organizations in NATO member countries, CISA warns.
🛑 No link. No attachment. Just viewing the email. A Russian state-supported espionage group exploited a Zimbra zero-day for at least 5 months to steal passwords, 2FA recovery codes, organization directories, and 90 days of mail. Read how ZimReaper worked - https:// thehackernews.com/2026/07/russ ian-espionage-group-exploited.html
Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks https:// hackread.com/russian-hackers-z imbra-0-day-steal-emails-link-clicks/?utm_source=dlvr.it&utm_medium=%5Binfosec.exchange%5D
🏆 New Achievement! Zero-Day, Zero Interaction, Zero Mercy! HEALTH BAR DEPLETED. INTRODUCING: TA488 — Russian state-sponsored, patient as a glacier, and already inside your inbox since July 2025. Five months as an unknown threat. Five months of your emails, your contacts, your saved browser passwords, and — best of all — your two-factor recovery codes, all vacuumed up just because someone looked a
📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims. Listen/Read: https:// hackread.com/russian-hackers-z imbra-0-day-steal-emails-link-clicks/ # CyberSecurity # Zimbra # 0day # Vulnerability # Russia # TA488
A Russian state-supported group called LAUNDRY BEAR is stealing emails from Western governments and defense firms by exploiting a Zimbra webmail flaw that triggers the moment a victim opens a message. A 17-nation advisory warns the campaign is still running. #APT #infosec Nation-State · IntelFusions threat intelligence
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries https:// cyberscoop.com/russian-laundry -bear-zimbra-exploit/
A Russian espionage group exploited a Zimbra zero-day for five months, harvesting emails and 2FA codes. The November patch fixes the flaw but won't revoke stolen https:// deafnews.it/en/article/russia- exploits-zimbra-zero-day-patching-alone-wont-evict-the-spies
2026-W30 — Weekly Threat Roundup 🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required. 🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da… https:// threatnoir.com/weekly/2026-w30 # infosec # cybersecurity