WORLDHouse Democratic leadership breaks ranks on Massie Israel aid amendment, with caucus split near 50/50Aug 7, 2026
CRYPTORussian state hackers steal 90 days of email on open, no click requiredAug 7, 2026
EARNINGSAtkinsRealis Q2 2026 results draw contract demand from SPEA as nuclear growth continuesAug 7, 2026
REGULATORYHouse bill sets $10,000 ceiling on church protest fines in bipartisan pushAug 7, 2026
CRYPTOColdcard exploit pushes July crypto losses to $247M, second-worst month of 2026Aug 7, 2026
CRYPTOCLARITY Act delay hands Asian financial hubs an opening, First Digital CEO saysAug 7, 2026
MACROTrump says Fed rate decision rests with full board, not Warsh aloneAug 7, 2026
EARNINGSCION Investment Corporation shifts capital toward buybacks as repurchase program reaches $130 millionAug 7, 2026
WORLDHouse Democratic leadership breaks ranks on Massie Israel aid amendment, with caucus split near 50/50Aug 7, 2026
CRYPTORussian state hackers steal 90 days of email on open, no click requiredAug 7, 2026
EARNINGSAtkinsRealis Q2 2026 results draw contract demand from SPEA as nuclear growth continuesAug 7, 2026
REGULATORYHouse bill sets $10,000 ceiling on church protest fines in bipartisan pushAug 7, 2026
CRYPTOColdcard exploit pushes July crypto losses to $247M, second-worst month of 2026Aug 7, 2026
CRYPTOCLARITY Act delay hands Asian financial hubs an opening, First Digital CEO saysAug 7, 2026
MACROTrump says Fed rate decision rests with full board, not Warsh aloneAug 7, 2026
EARNINGSCION Investment Corporation shifts capital toward buybacks as repurchase program reaches $130 millionAug 7, 2026

Russian state hackers steal 90 days of email on open, no click required

Ninety days of archived email, along with passwords and two-factor authentication tokens, flows to attacker-controlled servers the moment a vulnerable Zimbra webmail client renders a malicious message, according to a joint advisory from…

By Sofia Almeida·Aug 7, 2026·2 min read·crypto

Key takeaways

  • Russian state-sponsored group Laundry Bear (tracked by Microsoft as Void Blizzard) exploited a Zimbra webmail flaw to steal up to 90 days of email, passwords and two-factor tokens the moment a malicious message is rendered, per a joint CISA, NSA, FBI and allied advisory.
  • The vulnerability, CVE-2025-66376, is a cross-site scripting flaw in the Classic UI of certain Zimbra Collaboration Suite versions that runs malicious JavaScript with no attachment opened or link clicked.
  • Laundry Bear used the flaw as a zero-day before Zimbra patched it in November 2025, and more than 10 Western organizations have been hit since July 2025.
  • The attackers collect up to 90 days of mailbox content, account email and password, the Global Address List, and session tokens, and create a 'ZimbraWeb' application passcode that survives password resets to keep access.
  • Stolen data is exfiltrated via Flowerbed, which hides smaller payloads in DNS requests while larger mailbox archives leave over encrypted HTTPS.

Ninety days of archived email, along with passwords and two-factor authentication tokens, flows to attacker-controlled servers the moment a vulnerable Zimbra webmail client renders a malicious message, according to a joint advisory from CISA, the NSA, the FBI and allied cyber authorities. The operation belongs to Laundry Bear, a Russian state-sponsored group Microsoft tracks as Void Blizzard. More than 10 Western organizations have been hit since July 2025.

CVE-2025-66376: how the exploit runs

The flaw is a cross-site scripting vulnerability in the Classic user interface of certain Zimbra Collaboration Suite versions. Zimbra serves governments, schools, businesses and other organizations as an alternative to Microsoft Exchange or Google Workspace. Laundry Bear embeds malicious JavaScript inside specially crafted HTML emails; that code executes automatically when a vulnerable Zimbra browser session displays the message. No attachment opened, no link clicked. CISA labels the technique a zero-click exploit. Proofpoint calls it a "half-click" attack because the email must reach the screen, whether fully opened or visible in a preview pane.

The group treated CVE-2025-66376 as a zero-day before Zimbra released a patch in November 2025. CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalog. Organizations that skipped the update remain fully exposed.

What the attackers collect and how they stay in

The malicious code targets four categories: up to 90 days of mailbox content, the account's email address and password, the organization's Global Address List, and active session cookies or authentication tokens. A stolen session token lets attackers re-enter an account without completing a new login. Laundry Bear also generates a fresh Zimbra application passcode, which legacy clients use to connect via IMAP or ActiveSync when modern time-based authentication is unavailable. CISA has specifically flagged passcodes labeled "ZimbraWeb." Because application passcodes survive a standard password reset, attacker access can persist long after a user believes the account is secured.

Stolen data exits through Flowerbed, a collection framework that encodes smaller payloads inside DNS requests, blending into normal DNS traffic volume. Larger mailbox archives leave via encrypted HTTPS.

Target sectors and infrastructure

Laundry Bear has focused on organizations connected to Russian strategic interests since at least 2024. Confirmed sectors span defense, government, education, energy, law enforcement, media, nonprofits and technology. The group's targeting has concentrated on NATO member states and entities supporting Ukraine. Dutch intelligence agencies identified Laundry Bear in May 2025 after linking it to a 2024 breach of the Dutch National Police that exposed personnel data.

Proofpoint found the group sent phishing emails from attacker-controlled Proton Mail accounts and from addresses already compromised in earlier intrusions. CISA's published indicators of compromise include domains impersonating Zimbra infrastructure: mailnalysis.com, zimbrastat.com, zimbra-metadata.com and zmailanalytics.com.

Share
Source: foxnews.com
© 2026 NewsMeter

Frequently asked

What is CVE-2025-66376?

It is a cross-site scripting vulnerability in the Classic user interface of certain Zimbra Collaboration Suite versions that lets malicious JavaScript execute automatically when a vulnerable browser session displays a crafted HTML email.

Do I have to click anything to be compromised?

No; CISA calls it a zero-click exploit because the code runs the moment the email is rendered, though Proofpoint terms it a 'half-click' attack since the message must reach the screen, even in a preview pane.

Why can attacker access persist after a password reset?

Laundry Bear generates a fresh Zimbra application passcode labeled 'ZimbraWeb,' and because application passcodes survive a standard password reset, access can continue after a user believes the account is secured.

Who is behind the attacks and who are the targets?

The attacker is Laundry Bear, a Russian state-sponsored group Microsoft tracks as Void Blizzard, and it has targeted NATO member states and entities supporting Ukraine across sectors including defense, government, education, energy, law enforcement, media, nonprofits and technology.

When was the vulnerability patched?

Zimbra released a patch in November 2025, after which CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, but organizations that skipped the update remain fully exposed.