Critical

Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries

CyberScoop
Actively Exploited

Overview

A Russian espionage group known as Laundry Bear has been exploiting a zero-day vulnerability in Zimbra for five months before it was patched in July 2025. Despite the patch, the group continues to target vulnerable systems to steal sensitive data from Western countries. This ongoing activity raises concerns about the security of email platforms and the potential for data breaches that could affect numerous organizations. As companies rely on these systems for communication, the implications of such attacks could be significant, leading to unauthorized access to confidential information. Organizations using Zimbra should prioritize updating their systems to protect against this threat.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Zimbra email platform
  • Action Required: Update Zimbra to the latest version as of July 2025 to patch the vulnerability.
  • Timeline: Ongoing since five months prior to July 2025

Original Article Summary

Laundry Bear exploited a zero-day vulnerability for five months before it was patched in July 2025, and the group is still actively exploiting vulnerable environments. The post Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries appeared first on CyberScoop.

Impact

Zimbra email platform

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since five months prior to July 2025

Remediation

Update Zimbra to the latest version as of July 2025 to patch the vulnerability.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Zero-day, Exploit, Vulnerability, and 2 more.

Related Coverage

Nation-State Threat Actors Explained

SCM feed for Latest

This article discusses the characteristics of nation-state threat actors and how they differ from other types of cyber attackers. It emphasizes the importance for cybersecurity professionals to accurately identify these actors in order to assess threat intelligence effectively. Nation-state actors are typically backed by governments and have access to significant resources, making their tactics more sophisticated than those of independent hackers or criminal groups. Understanding these distinctions can help organizations prioritize their defenses and respond appropriately to potential threats. The article serves as a guide for security teams to enhance their threat assessments and better prepare for attacks that may originate from state-sponsored entities.

Jul 23, 2026

New Dolphin X malware uses AI to rank high-value targets

BleepingComputer

A new malware called Dolphin X has emerged, functioning as a remote access trojan (RAT) that utilizes artificial intelligence to assess and rank the value of its victims. By scoring infected users, cybercriminals can prioritize their targets based on the potential payoff. This AI-driven profiling allows attackers to focus their efforts on high-value individuals or organizations, making the threat particularly concerning for anyone at risk of being compromised. The introduction of such technology could lead to more targeted and effective cyberattacks, raising alarms for security professionals and users alike. As the malware spreads, it highlights the evolving tactics of cybercriminals and the need for enhanced security measures.

Jul 23, 2026

Fake Claude app promoted by Bing ads pushes SectopRAT malware

BleepingComputer

A recent malvertising campaign on Bing is promoting a fake desktop application that masquerades as the Claude AI tool. This fake installer is hosted on a legitimate domain for Claude.ai and is designed to deliver a malware known as SectopRAT. Users searching for Claude on Bing may unknowingly download this malicious software, which can compromise their systems. The presence of such malware poses risks not only to individual users but can also affect organizations if their employees inadvertently install it on work devices. Cybersecurity experts are urging users to be cautious when downloading software from search engine ads, as this incident illustrates the potential dangers of malvertising.

Jul 23, 2026

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

The Hacker News

A Russian state-sponsored espionage group has exploited a previously unknown vulnerability in Zimbra's webmail client to gain unauthorized access to Western email accounts. This attack allowed the hackers to read the last 90 days of emails, access the entire email directory, and retrieve saved passwords and two-factor authentication recovery codes. The exploitation was triggered simply by opening a malicious email. The U.S. National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA), along with their partners, have alerted organizations to this ongoing threat. This incident raises significant concerns about the security of email communications, especially for organizations using Zimbra, as it underscores the need for vigilance against such sophisticated attacks.

Jul 23, 2026

Hackers abuse Notepad++ plugins to stealthily install malware

BleepingComputer

Ukraine's CERT has reported that attackers are using a combination of the legitimate Notepad++ application and a malicious utility named LunchPoke, which is disguised as a plugin. This malicious tool is designed to install malware on victims' systems and maintain a presence even after initial infection. Users who download the compromised software may unknowingly introduce this malware into their systems, putting their data and security at risk. This incident serves as a reminder for users to be cautious about the sources from which they download software, as even trusted applications can be manipulated to deliver harmful payloads. The situation emphasizes the need for vigilance in software installation practices.

Jul 23, 2026

Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations

Infosecurity Magazine

Russian hackers have reportedly launched a state-backed campaign targeting Western organizations by exploiting a serious vulnerability in the Zimbra Collaboration Suite. This 'zero-click' attack allows hackers to gain access without any user interaction, making it particularly dangerous. International agencies have issued a joint alert, urging organizations using Zimbra to take immediate precautions. The vulnerability is significant, as it can lead to unauthorized access to sensitive data. Companies and users utilizing this software need to stay vigilant and ensure their systems are updated to protect against potential breaches.

Jul 23, 2026