CVE Tools

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

Dark ReadingBy Rob Wright

Reported exploitedZimbra Collaboration SuiteLaundry Bear

Our summary

Russian state-backed threat actors have been exploiting a critical zero-day vulnerability in Zimbra Collaboration Suite (CVE-2025-66376) to target U.S., Ukrainian, and other Western government and enterprise networks since July 2025. The flaw allows attackers to execute a so-called 'half-click' phishing attack—requiring only that a user view a malicious email within a vulnerable version of Zimbra webmail. This method bypasses traditional phishing defenses and enables adversaries to exfiltrate sensitive data. Multiple intelligence and cybersecurity agencies warn that the exploit is being used by the APT group Laundry Bear, with ties to Russian intelligence, to gather information for strategic advantage.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store