In brief: Laundry Bear exploits an unpatched Zimbra security vulnerability using “half-click” phishing emails that are triggered by opening or previewing a message to attack US and Ukrainian targets.
A state-sponsored hacker group known as Laundry Bear is exploiting a zero-day vulnerability in Zimbra, deploying “half-click” phishing emails that can be activated simply by opening or previewing a message.
A threat group known as Laundry Bear, believed to be state-sponsored, is exploiting a previously unknown security vulnerability in the Zimbra platform in its attacks. The campaign is targeting entities in the United States and Ukraine.
The attackers are sending so-called “half-click” phishing emails, where simply opening or previewing a message in Zimbra is sufficient to activate the exploit. Unlike traditional phishing attacks that require deliberate clicking on a link, this method eliminates the need for explicit user interaction.
For CISOs, this presents a significant detection and prevention challenge: since message preview alone serves as an attack vector, defensive measures require vulnerability scanning of email systems and a strict patch management strategy for Zimbra installations. The zero-day nature of the vulnerability makes it difficult to deploy signature-based solutions.
Source: www.darkreading.com · Published 23 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.