NewsMeter

Russian state hackers steal 90 days of email on open, no click required

8/7/2026

Ninety days of archived email, along with passwords and two-factor authentication tokens, flows to attacker-controlled servers the moment a vulnerable Zimbra webmail client renders a malicious message, according to a joint advisory from CISA, the NSA, the FBI and allied cyber authorities.

The operation belongs to Laundry Bear, a Russian state-sponsored group Microsoft tracks as Void Blizzard. More than 10 Western organizations have been hit since July 2025.

CVE-2025-66376: how the exploit runs The flaw is a cross-site scripting vulnerability in the Classic user interface of certain Zimbra Collaboration Suite versions.

Zimbra serves governments, schools, businesses and other organizations as an alternative to Microsoft Exchange or Google Workspace.

Keep reading

Read the full story

Open on NewsMeter