Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Reported exploitedZimbra Collaboration SuiteLaundry BearOur summary
A Russian state-backed hacking group has been exploiting a zero-day vulnerability in Zimbra's webmail client to steal sensitive data, including email archives and two-factor authentication (2FA) recovery codes. The flaw, CVE-2025-66376, allows attackers to execute malicious JavaScript simply by viewing a crafted HTML email. This vulnerability was actively used between July 2025 and February 2026 against government and commercial organizations in Western countries, Ukraine, and other regions. Zimbra released patches for affected versions in November 2025, but users must manually review compromised accounts and invalidate stolen credentials.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.