FILTERING BY: CLEAR FILTER

Laundry Bear Exploits Zimbra Zero-Click Vulnerability CVE-2025-66376 for Espionage

Russian state-sponsored actor Laundry Bear (Void Blizzard/TA488) has executed a large-scale espionage campaign targeting Zimbra Collaboration Suite (ZCS) versions prior to 10.1.13 and 10.0.18. Exploiting CVE-2025-66376, a stored XSS vulnerability triggered by improper sanitization of CSS @import directives, attackers achieve zero-click code execution when a target views a crafted email. The operation utilizes the 'Ulej' tool for session and 2FA backup code harvesting and the 'Flowerbed' Python framework for data exfiltration via Dockerized infrastructure. Impacted entities include government, defense, and energy sectors, with the loss of 90 days of mailbox content and browser credentials. Immediate patching to ZCS 10.1.13 or 10.0.18 is required.


LINK COPIED TO CLIPBOARD