<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Russian Hackers Exploited Zimbra Zero-Day to Target US and Ukrainian Organizations

Russian hackers Laundry Bear exploited a Zimbra flaw to breach US and Ukrainian servers, posing ongoing risks to unpatched systems.
Content Team

A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day vulnerability that only required victims to open or preview an email — no clicking required.

Zimbra patched the flaw in November 2025, but the campaign ran undetected for months. Proofpoint, which tracked the group as TA488, says operations appeared to stop in February after initial detection. Organizations still running unpatched Zimbra instances remain at risk.

Source: Dark Reading

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo