#1
The Hacker News
general
July 23, 2026 at 18:36 UTC
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
By [email protected] (The Hacker News)
AI Summary
Russian state-sponsored group 'Laundry Bear' exploited a Zimbra zero-day for five months before a July 2025 patch, using a zero-click 'half-click' phishing technique requiring only that a victim open or preview a message. The payload exfiltrates the last 90 days of email, the full organizational email directory, browser-saved passwords, and 2FA recovery codes. NSA, CISA, and partner agencies issued a joint advisory, making this a critical defensive priority for any organization running Zimbra webmail.
Relevance score: 88.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →