Zimbra zero-click vulnerability exploited by Russian state hackers for email theft
The Russian group Laundry Bear combines phishing with a patched Zimbra flaw to access email without user interaction, targeting organizations still running vulnerable servers.
State-sponsored campaign targets email infrastructure
CISA warns that Laundry Bear, a Russian state-sponsored threat group also tracked as Void Blizzard, is actively targeting organizations using Zimbra Collaboration email servers. The campaign combines phishing techniques with exploitation of a now-patched vulnerability that enables access without requiring targets to click malicious links.
The zero-click nature of the Zimbra flaw makes it particularly dangerous for organizations that have not applied available patches. Attackers gain access to email accounts simply by sending specially crafted messages that trigger the vulnerability when viewed.
Patch status determines exposure
Organizations running Zimbra Collaboration servers should verify they have applied the security update addressing this vulnerability. The patch has been available, but the active exploitation campaign indicates many deployments remain vulnerable.
The combination of state-sponsored resources and a zero-click exploit makes this threat particularly serious for government agencies, critical infrastructure operators, and organizations handling sensitive communications. Email security depends on maintaining current patch levels across collaboration platforms.