The bottom line: A zero-day vulnerability in Zimbra enabled Russian attackers to exfiltrate 90 days of email history, directories, stored passwords, and 2FA recovery codes by simply opening a message.
A Russian state-sponsored espionage group accessed emails from Western organizations for months through a previously unknown security flaw in the Zimbra webmail client. The NSA, CISA and partners have made the campaign public.
The Russian espionage group deployed malware that was activated simply by opening an infected email. The payload specifically targeted data: the last 90 days of email history, the organization’s complete email directory, passwords stored in the browser, and two-factor authentication (2FA) recovery codes.
This is a critical combination from a security perspective: with access to old emails, passwords, and 2FA recovery codes, attackers can not only compromise accounts but also remain undetected long-term. The use of a zero-day vulnerability points to highly targeted activities, where attacks succeeded without prior public warning.
The NSA, CISA and allied agencies have now publicly documented this campaign. For CISOs, Zimbra implementations must be immediately checked for indicators of compromise, and systems should be isolated or taken offline if a patch is not available in a timely manner. The technical details of the campaign aid in forensic analysis for affected organizations and the search for further unauthorized access.
Source: thehackernews.com · Published July 23, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.