Live Cybersecurity News Ticker | Codekeeper

Russian Hackers Exploited Zimbra Zero-Day to Target US and Ukrainian Organizations

Written by Content Team | Jul 29, 2026, 12:23:57 PM

A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day vulnerability that only required victims to open or preview an email — no clicking required.

Zimbra patched the flaw in November 2025, but the campaign ran undetected for months. Proofpoint, which tracked the group as TA488, says operations appeared to stop in February after initial detection. Organizations still running unpatched Zimbra instances remain at risk.

Source: Dark Reading