Zimbra zero-click vulnerability exploited by Russian state hackers for email theft

The Russian group Laundry Bear combines phishing with a patched Zimbra flaw to access email without user interaction, targeting organizations still running vulnerable servers.

Abstract representation of targeted email compromise
AI-generated illustration · Sylvaris

State-sponsored campaign targets email infrastructure

CISA warns that Laundry Bear, a Russian state-sponsored threat group also tracked as Void Blizzard, is actively targeting organizations using Zimbra Collaboration email servers. The campaign combines phishing techniques with exploitation of a now-patched vulnerability that enables access without requiring targets to click malicious links.

The zero-click nature of the Zimbra flaw makes it particularly dangerous for organizations that have not applied available patches. Attackers gain access to email accounts simply by sending specially crafted messages that trigger the vulnerability when viewed.

Patch status determines exposure

Organizations running Zimbra Collaboration servers should verify they have applied the security update addressing this vulnerability. The patch has been available, but the active exploitation campaign indicates many deployments remain vulnerable.

The combination of state-sponsored resources and a zero-click exploit makes this threat particularly serious for government agencies, critical infrastructure operators, and organizations handling sensitive communications. Email security depends on maintaining current patch levels across collaboration platforms.

sources
more in Security
California aftermarket car security systems vulnerable to Bluetooth hijacking via shared encryption key Millions of vehicles with dealer-installed KARR/SWDS security systems use identical Bluetooth encryption keys, allowing attackers to unlock and start cars remotely. Oracle ships 1,449 security patches in quarterly update as AI-driven vulnerability discovery accelerates The patch volume reflects AI tools finding vulnerabilities faster than human researchers, forcing defenders to manage larger workloads quarterly. GitHub reduces public bug bounty payouts as AI-generated reports overwhelm security team GitHub is lowering public bug bounty rewards and restricting first-time researcher access after AI-generated security reports created unsustainable volume for the security team to triage.