Russian Hackers Exploited Zimbra Zero-Day to Target US and Ukrainian Organizations
Russian hackers Laundry Bear exploited a Zimbra flaw to breach US and Ukrainian servers, posing ongoing risks to unpatched systems.
By
Content Team
ON THIS PAGE
Want more insights like this?
Subscribe to our newsletter to get the latest software protection strategies delivered to your inbox.
By submitting your email, you consent to Codekeeper contacting you and agree to our privacy policy.
A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day vulnerability that only required victims to open or preview an email — no clicking required.
Zimbra patched the flaw in November 2025, but the campaign ran undetected for months. Proofpoint, which tracked the group as TA488, says operations appeared to stop in February after initial detection. Organizations still running unpatched Zimbra instances remain at risk.
Source: Dark Reading
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo