Skip to content

Russians Exploit Zimbra Vulnerability for Phishing Attacks on Email Servers

To the point: Russian hacker group Laundry Bear combines phishing with a Zimbra security vulnerability to infiltrate email systems.

The US Cybersecurity and Infrastructure Security Agency (CISA) warns of the Russian state-sponsored hacker group Laundry Bear (also known as Void Blizzard), which attacks Zimbra Collaboration servers using phishing and an already-patched security vulnerability to steal emails.

The hacker group Laundry Bear, an organization attributed to Russian intelligence services, conducts targeted attacks against organizations using Zimbra Collaboration as their email solution. The attackers combine classical phishing methods with exploitation of a security vulnerability in Zimbra for which a patch is already available.

The interplay of both attack vectors significantly increases the risk: while phishing emails open the entry point, the Zimbra vulnerability enables deeper infiltration and direct access to the email infrastructure. This allows the attackers to extract large quantities of sensitive data without relying on user authentication.

For CISOs, this creates a dual imperative for action: First, all Zimbra installations must be updated immediately to the current version to close the vulnerability. Second, it requires enhanced email security measures to detect and block phishing content. Organizations should verify whether their Zimbra systems have been updated in recent months and, if necessary, conduct forensic analysis.


Source: www.bleepingcomputer.com · Published 23 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: