Russian hackers exploit Zimbra zero-click flaw for email theft
By Lawrence Abrams
AI Summary
CISA and partner agencies issued a joint advisory warning that Russian state-sponsored group Laundry Bear (also known as Void Blizzard) is actively exploiting a now-patched zero-click vulnerability in Zimbra Collaboration webmail servers. The 'half-click' attack requires only that a victim open or preview a phishing email, triggering payload delivery that steals up to 90 days of email, the organization's full email directory, browser-saved passwords, and 2FA recovery codes. The vulnerability was exploited for approximately five months before being patched in July 2025, and vulnerable unpatched environments remain at risk.
Relevance score: 88.0/100
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →