Updated
Updated · Fox News · Aug 7
Russian Hackers Steal 90 Days of Email via Zimbra Flaw at 10+ Western Organizations
Updated
Updated · Fox News · Aug 7

Russian Hackers Steal 90 Days of Email via Zimbra Flaw at 10+ Western Organizations

1 articles · Updated · Fox News · Aug 7

Summary

  • CISA said Russia-linked Laundry Bear has breached more than 10 Western organizations since July 2025 by exploiting CVE-2025-66376 in unpatched Zimbra Collaboration Suite servers.
  • The flaw lets malicious JavaScript run when a user merely opens or previews a crafted HTML email, enabling theft of passwords, two-factor tokens and up to 90 days of messages.
  • Laundry Bear also creates unauthorized Zimbra application passcodes that can preserve mailbox access even after a victim changes the main account password.
  • CISA said the group exfiltrates stolen data through DNS and HTTPS, while also using fake Zimbra login pages and lookalike domains to capture credentials and session cookies.
  • Zimbra patched the bug in November 2025, but agencies warned governments, defense, energy, education, media and Ukraine-linked targets remain exposed if they have not updated and checked for compromise.

Insights

What hidden backdoors remain in unpatched networks today, long after the devastating 2025 Zimbra zero-click cyberattacks?
How did a simple email preview allow hackers to silently drain Western intelligence for months before the late 2025 patch?

Inside the 2026 Laundry Bear Campaign: AI-Driven Zero-Click Exploits and the Global Zimbra Breach

Overview

In July 2025, the Russian state-backed group Laundry Bear began exploiting a zero-day vulnerability in Zimbra mail servers by sending specially crafted HTML emails. These emails triggered the ZimReaper payload, which harvested sensitive data and created a secret 'ZimbraWeb' password, giving attackers ongoing access and bypassing multi-factor authentication. The attackers used compromised servers to spread further, all while staying hidden for months. Artificial intelligence helped Laundry Bear quickly build and adapt these stealthy attacks. After Zimbra patched the flaw and security agencies exposed the campaign in July 2026, organizations started shifting to Zero Trust security models to defend against such advanced threats.

...