CVE Tools

Western cyber agencies warn of Russian hacks of Zimbra servers

Risky Business NewsBy Catalin Cimpanu

Reported exploitedZimbra Collaboration SuiteLaundry Bear

Our summary

Western cybersecurity agencies have issued warnings about a Russian hacking campaign exploiting a zero-day vulnerability in Zimbra Collaboration Suite. The flaw, CVE-2025-66376, allows attackers to inject malicious code into webmail clients through CSS @import, enabling credential theft and data exfiltration. The threat group behind the attacks is linked to Laundry Bear (also known as Void Blizzard or TA488), with evidence of extensive targeting of Ukrainian and NATO-related organizations.

Read at Risky Business News

Risky Business News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store