< Back to all clusters
[TECHNOLOGY] · United States, United Kingdom, Netherlands, Canada, Australia · 18 sources

Russian Laundry Bear exploits Zimbra zero‑click flaw to steal emails across NATO allies

A Russian state‑backed hacking group known as Laundry Bear (also tracked as Void Blizzard) exploited a stored cross‑site scripting vulnerability (CVE‑2025‑66376) in the Zimbra Collaboration Suite’s classic web client. The “zero‑click” or “half‑click” exploit required only that a user view a malicious email, allowing the code to run automatically and exfiltrate up to 90 days of email, the organization’s address book, saved passwords and two‑factor‑authentication recovery codes.

Law‑enforcement and intelligence agencies from the United States, United Kingdom, Netherlands, Canada, Australia, New Zealand, Denmark, the Czech Republic and other European partners issued a 31‑page joint advisory, warning that the campaign first targeted Ukrainian entities before expanding to users in NATO member states. British Security Minister Dan Jarvis said, “It’s particularly concerning that these thugs tested their methods on victims in Ukraine, before targeting members of NATO.”

The group is alleged to operate with support from Russian security services and is linked to the Russian cybersecurity firm Yutek‑NN. Zimbra’s owner, Synacor, released a patch in November 2025, and the vulnerability was added to the U.S. CISA Known Exploited Vulnerabilities catalog in March 2026. Agencies continue to urge organizations that have not yet applied the update to do so urgently.

Sources

about 3 hours ago