Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Download: AI doomers, whistleblowing agents, and de-aged livers

    September 15, 2026

    Inside the Inference Hardware Revolution Of 2026

    September 15, 2026

    What must happen for AI’s trillion-dollar gamble to pay off

    September 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Download: AI doomers, whistleblowing agents, and de-aged livers
    • Inside the Inference Hardware Revolution Of 2026
    • What must happen for AI’s trillion-dollar gamble to pay off
    • When AI agents cheated at math, other AI agents blew the whistle on them
    • ‘I Like My Big Rat Wife’: Meet the People Using Chatbots to Write Custom Fiction
    • Donated livers can be made biologically younger
    • Responsible AI for Higher Education
    • The Real AI Disruption Isn’t the Technology. It’s the Company.
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Russian hackers exploit Zimbra zero-click flaw for email theft
    Cybersecurity

    Russian hackers exploit Zimbra zero-click flaw for email theft

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 23, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Phishing
    Share
    Facebook Twitter LinkedIn Pinterest Email

    CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability.

    According to CISA, Laundry Bear has targeted and compromised users in organizations associated with the Defense Industrial Base (DIB), federal and local government, education, energy, law enforcement, media, non-governmental organizations, and technology.

    The attackers exploit the Zimbra CVE-2025-66376 flaw, a cross-site scripting (XSS) vulnerability affecting Zimbra Collaboration Suite’s Classic UI.

    The flaw allows JavaScript embedded in specially crafted HTML emails to execute automatically when a victim views the message, enabling attackers to steal account data without requiring the user to click a link or visit a phishing site.

    According to CISA, Laundry Bear exploited the flaw as a zero-day before Zimbra patched it in November 2025 and continues to target organizations running unpatched servers. The vulnerability was later tagged by CISA as actively exploited in attacks.

    CISA says Laundry Bear’s exploit is used to automatically collect and send the victim’s last 90 days of emails, email address, password, Global Address List (GAL), and two-factor authentication (2FA) tokens.

    The attackers also create and send back a new Zimbra application passcode, which is used by legacy email clients like IMAP or ActiveSync that do not support the TOTP authentication flows. Using a passcode allows the attackers to retain access to the email account while bypassing MFA.

    According to CISA, the malware exfiltrates stolen information over both DNS and HTTPS to an actor-controlled server running the group’s “Flowerbed” collection framework.

    Smaller data is encoded and transmitted in DNS A-record queries, while larger payloads, including mailbox data, are uploaded over HTTPS as compressed archives to the attacker-controlled servers.

    In addition to exploiting the Zimbra flaw, Laundry Bear also utilizes adversary-in-the-middle (AiTM) phishing kits designed to impersonate legitimate Zimbra login portals, stealing credentials and session cookies, allowing the attackers to gain access to targets’ email accounts.

    CISA released IOCs that show the campaign used sites that impersonate Zimbra infrastructure, using domain names like ‘mailnalysis.com’, ’emailanalytics.com.ua’, ‘zimbrastat.com’, ‘zimbra-metadata.com’, ‘istc-cloud.com’, and ‘zmailanalytics.com’.

    The advisory recommends that organizations using Zimbra:

    • Update to the latest version of the software to install all available security updates.
    • Review the published indicators of compromise.
    • Investigate systems for connections to the identified domains and IP addresses.
    • Monitor for suspicious authentication activity.
    • Revoke any unauthorized application passcodes, especially those with the ‘ZimbraWeb’.
    • Review accounts for unauthorized mailbox access.

    CISA also recommends implementing phishing-resistant multi-factor authentication where possible.

    Laundry Bear targeted governments, police, and Ukraine

    The Laundry Bear hacking group was first attributed to cyberespionage attacks in May 2025 by the Dutch intelligence agencies.

    The Dutch agencies publicly attributed the group to a 2024 compromise of the Dutch National Police that exposed the personal information of police personnel and led to the identification of a previously unknown Russian espionage group.

    Microsoft tracks the same group under the name Void Blizzard.

    Since at least 2024, the group has focused on intelligence collection against organizations aligned with Russian strategic interests, primarily targeting NATO member states and Ukraine.

    Microsoft has also documented successful compromises of organizations supporting Ukraine, including entities in the defense, transportation, and aviation sectors.

    Earlier this year, BleepingComputer reported on a separate Laundry Bear campaign targeting Ukraine’s military using charity-themed phishing emails to deliver malware disguised as donation requests.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Email exploit Flaw hackers Russian theft ZeroClick Zimbra
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    These Russian Mathematicians Taught AI Models How to Talk to Each Other Without Using Words

    September 2, 2026

    A fundamental flaw leaves LLMs strikingly vulnerable to attack

    July 31, 2026

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    The best VPN routers of 2026: Expert tested and reviewed

    June 14, 20263 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • The Download: AI doomers, whistleblowing agents, and de-aged livers
    • Inside the Inference Hardware Revolution Of 2026
    • What must happen for AI’s trillion-dollar gamble to pay off
    • When AI agents cheated at math, other AI agents blew the whistle on them
    • ‘I Like My Big Rat Wife’: Meet the People Using Chatbots to Write Custom Fiction

    The Download: AI doomers, whistleblowing agents, and de-aged livers

    September 15, 2026

    Inside the Inference Hardware Revolution Of 2026

    September 15, 2026

    What must happen for AI’s trillion-dollar gamble to pay off

    September 15, 2026

    When AI agents cheated at math, other AI agents blew the whistle on them

    September 15, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.