The Russian state-backed threat actor Laundry Bear is exploiting an unspecified vulnerability in Zimbra Collaboration Suite (ZCS) to gain unauthorized access and steal emails from government and commercial networks. The campaign has been active since at least July 2025, according to a joint advisory from multiple international cybersecurity agencies. Specific CVE, CVSS score, affected version ranges, fixed versions, and workarounds are not provided in the source article.
Russian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform. Laundry Bear (also known as Void Blizzard, CL-STA-1114, and TA488) has been running the campaign since July 2025, according to a joint advisory from the NSA, FBI, CISA, and cybersecurity agencies from the Netherlands, UK, Australia, Canada, and a dozen other countries. “Laundry Bear’s … More → The post Russian hackers exploit unpatched Zimbra servers to steal emails appeared first on Help Net Security .