FILTERING BY: CLEAR FILTER

Laundry Bear Exploits Zero-Click Zero-Day in Zimbra Webmail

Kremlin-backed threat actor Laundry Bear executed a global cyberespionage campaign targeting Western organizations by exploiting a zero-day vulnerability in Zimbra webmail servers. The attack utilized a zero-click phishing vector combined with JavaScript injection to bypass user interaction and steal credentials, enabling large-scale unauthorized email exfiltration. While a patch was released in July 2025, the vulnerability was actively exploited for five months prior. Current risk remains high for organizations operating unpatched or improperly secured Zimbra environments, as the group continues to target these vulnerabilities for strategic intelligence gathering.


LINK COPIED TO CLIPBOARD