Russian hackers exploited Zimbra zero
Russian state-sponsored cybercriminals exploited a zero-day vulnerability in the Zimbra email and collaboration platform to conduct espionage against Western targets, primarily military and government agencies, according to a recent report by Tech Radar.Proofpoint reports that the threat group TA488, also known as Laundry Bear or Void Blizzard, leveraged a cross-site scripting (XSS) vulnerability, tracked as CVE-2025-66376, in Zimbra's web-based email service. This "half-click exploit" allowed attackers to compromise systems simply when victims viewed malicious emails, without requiring any further interaction. The campaign targeted NATO, Ukrainian government organizations, and entities within the defense industrial base. After gaining access, TA488 exfiltrated emails, passwords, two-factor authentication tokens, and other sensitive information. The group consistently targeted these entities for at least a year before their activity ceased in February 2026, following the public disclosure of their methods by security researchers, which led to their disappearance.Tech Radar
Source: Threat Management, Threat Intelligence
Russian hackers exploited Zimbra zero-day in espionage campaigns
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.