Skip to content

Laundry Bear Exploits Zimbra CVE-2025-66376 for Email Exfiltration

Key point: Laundry Bear exploited CVE-2025-66376 in Zimbra to access email archives without user interaction.

The Russian hacker group Laundry Bear has exploited a vulnerability in Zimbra installations to steal emails directly—without requiring users to click links or open attachments. A government advisory provides concrete indicators and protective measures.

The Russian hacker group Laundry Bear has exploited a vulnerability in Zimbra systems to gain access to email archives. The vulnerability CVE-2025-66376 enabled attackers to gain direct access to mailboxes without users becoming victims of phishing attacks with malicious links or files.

A joint advisory from multiple government agencies documents the campaign and provides indicators of compromise (IoCs). The warning contains concrete technical characteristics that assist in detecting access traces. The advisory directly addresses security officials and calls for immediate inspection of Zimbra installations for exposed systems.

For CISOs, this attack vector represents increased urgency: the absence of the need for user interaction reduces the effectiveness of awareness training and lowers the barrier to entry for successful compromises. Zimbra administrators should immediately apply patches and integrate the provided IoCs into their security tools to detect suspicious activities.


Source: www.security-insider.de · Published 27 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 of the EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: