CVE Tools

Russian hackers exploit unpatched Zimbra servers to steal emails

Help Net SecurityBy Sinisa Markovic

Reported exploitedZimbra Collaboration SuiteLaundry Bear

Our summary

A Russian state-backed hacking group called Laundry Bear has been exploiting an unpatched vulnerability in Zimbra Collaboration Suite (CVE-2025-66376) to infiltrate government and corporate networks since July 2025. The flaw, a cross-site scripting issue fixed in November 2025, allows attackers to steal sensitive data simply by having users view a malicious email. Multiple U.S. and international cybersecurity agencies warn that the threat actors continue to use this exploit against unpatched systems, targeting sectors including defense, government, education, and law enforcement. Organizations are urged to apply updates and monitor for suspicious activity.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store