Home / Jul 25, 2026 / Story
0
#1 The Hacker News general July 23, 2026 at 18:36 UTC

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

By [email protected] (The Hacker News)

AI Summary

Russian state-sponsored group 'Laundry Bear' exploited a Zimbra zero-day for five months before a July 2025 patch, using a zero-click 'half-click' phishing technique requiring only that a victim open or preview a message. The payload exfiltrates the last 90 days of email, the full organizational email directory, browser-saved passwords, and 2FA recovery codes. NSA, CISA, and partner agencies issued a joint advisory, making this a critical defensive priority for any organization running Zimbra webmail.

Relevance score: 88.0/100

# More from July 25