CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Russian hackers exploit Zimbra zero-click flaw for email theft

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3098

As cited

Copy frozen at (site build).

vulnerabilities

Russian hackers exploit Zimbra zero-click flaw for email theft

The Russian state-sponsored group Laundry Bear (also tracked as Void Blizzard) is exploiting a patched Zimbra Collaboration vulnerability alongside phishing attacks to steal email from targeted organizations. CISA has issued a warning about this active exploitation campaign. The vulnerability allows attackers to gain unauthorized access to email systems without user interaction.

Why it matters: Organizations running Zimbra Collaboration servers face immediate risk from a capable nation-state adversary; patch the vulnerability immediately and monitor for phishing attempts targeting your users.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Russian hackers exploit Zimbra zero-click flaw for email theft

The Russian state-sponsored group Laundry Bear (also tracked as Void Blizzard) is exploiting a patched Zimbra Collaboration vulnerability alongside phishing attacks to steal email from targeted organizations. CISA has issued a warning about this active exploitation campaign. The vulnerability allows attackers to gain unauthorized access to email systems without user interaction.

Why it matters: Organizations running Zimbra Collaboration servers face immediate risk from a capable nation-state adversary; patch the vulnerability immediately and monitor for phishing attempts targeting your users.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary