Security News

Cybersecurity news aggregator

🎣
CRITICAL Attacks Proofpoint

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

The Russian APT group Laundry Bear is exploiting a zero-click vulnerability (CVE-2025-66376, CVSS 7.2 HIGH) in Zimbra Collaboration Suite, where a malicious JavaScript payload hidden in emails from compromised accounts executes immediately upon opening, enabling mail and 2FA token exfiltration. Affected versions are Zimbra Collaboration Suite >= 10.0.0 < 10.0.18 and >= 10.1.0 < 10.1.13. The fixed versions are 10.0.18 and 10.1.13.
Read Full Article →

Leadership Cybercrime Nation-state Influence Operations Technology Cyber Daily® Click Here Podcast Go Subscribe to The Record ✉️ Free Newsletter Image: Le Vu via Unsplash James Reddick July 23rd, 2026 International alert spotlights Russia-linked attacks on Zimbra webmail Russian state-aligned hackers have been compromising governmental and commercial organizations throughout the West through zero-click phishing emails, federal agencies in the U.S., U.K., Europe, Australia and New Zealand warned on Thursday. The campaign, carried out by the advanced persistent threat (APT) group Laundry Bear, targets Zimbra Collaboration Suite’s webmail platform and exploits a vulnerability that was patched in November 2025. According to the advisory , the hackers carried out “extensive” targeting of Ukrainian entities before training their sights on U.S. and NATO organizations — evidence of “an increasing trend within Russian cyber threat groups to target Ukrainian users first—both as a priority target and as a testbench for malicious cyber techniques before broader global deployment.” “The covert and persistent nature of this activity, along with the absence of any known financial extortion, almost certainly indicates this group’s involvement in espionage activities with Russian government backing,” the agencies concluded. Palo Alto Networks’ Unit 42, which also published a report Thursday on the campaign, said the hackers targeted the defense and transportation sectors, as well as financial organizations in NATO member states, Ukraine, Commonwealth of Independent States countries and Africa. In its own advisory , Proofpoint said the group had compromised “government, high science, and defense industrial base targets in the United States.” Laundry Bear was first identified in May 2025 by Dutch intelligence agencies, which blamed the group for a series of hacks in the Netherlands, including on the national police. According to Microsoft, it has been active since at least 2024. Previous campaigns involved “unsophisticated” techniques, like password spraying and phishing attempts that required a recipient to click on a link. Since at least July 2025, the group has been deploying a novel exploit against the CVE-2025-66376 vulnerability in which a malicious JavaScript payload is hidden in emails sent from previously compromised email accounts. The payload is executed immediately when the emails are opened. According to the advisory, the hackers have attempted to exfiltrate the last 90 days of emails from a compromised account, passwords, contact lists, two-factor authentication tokens and other passcodes. In March 2026, the cybersecurity firm Seqrite described a zero-click phishing campaign exploiting Zimbra webmail that compromised a Ukrainian maritime agency . They attributed the activity with medium confidence to the Russian APT known as Fancy Bear. Dutch intelligence said Laundry Bear’s tactics “overlap with the modus operandi” of Fancy Bear but that they are different actors. Proofpoint researchers said the campaign reflects other activity in recent years from Russian and Belarusian hackers using cross-site scripting exploits “to pillage webmail servers.” The government agencies implored organizations using the Zimbra webmail service to immediately patch their software and, if patching is not feasible, to direct employees to use a different mail client. Nation-state News Get more insights with the Recorded Future Intelligence Cloud. Learn more. No previous article No new articles James Reddick has worked as a journalist around the world, including in Lebanon and in Cambodia, where he was Deputy Managing Editor of The Phnom Penh Post. He is also a radio and podcast producer for outlets like Snap Judgment. Briefs State Department imposes visa restrictions on foreign cyber scammers July 23rd, 2026 Major Australian energy supplier confirms customer data compromised July 23rd, 2026 Swiss train maker Stadler refuses Everest $12 million ransomware demand July 22nd, 2026 Federal agencies broaden alert on Iran-linked OT attacks July 22nd, 2026 New Kimsuky campaign compromised South Korean software vendors July 22nd, 2026 DNI nominee Clayton wins Senate panel’s approval July 21st, 2026 Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack July 21st, 2026 Taiwan to slow mobile data during national resilience drills July 21st, 2026 Kenya probes hack of president's website after bitcoin ransom demand July 21st, 2026 TAG-195 Upgrades MaaS Ecosystem with Modular Tools AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool Evaluating Mexico’s New Cybersecurity Plan State Digital Surveillance Risk Landscape Privacy About Contact Us © Copyright 2026 | The Record from Recorded Future News

Share this article