Laundry Bear exploits an unpatched Zimbra security vulnerability using “half-click” phishing emails that are triggered by opening or previewing a message to attack US and Ukrainian targets.
Zimbra 10.1.20 patches nine vulnerabilities, including a known SNMP-RCE flaw and four XSS weaknesses in the Classic Web Client that Russian groups have already exploited against Ukrainian infrastructure.