Russian hackers exploit unpatched Zimbra servers to steal emails
Overview
A Russian state-backed hacking group known as Laundry Bear has been exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform to infiltrate government and commercial networks. This campaign, active since July 2025, has targeted unpatched Zimbra servers to steal sensitive email communications. The warning comes from a joint advisory issued by multiple cybersecurity agencies, including the NSA and FBI, as well as partners from countries like the UK and Australia. With the ongoing exploitation of this vulnerability, organizations using ZCS are at increased risk of data breaches and should take immediate action to secure their systems. The situation emphasizes the need for timely software updates and vigilant security practices to protect sensitive information from state-sponsored cyber threats.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Zimbra Collaboration Suite (ZCS)
- Action Required: Organizations should immediately patch their Zimbra servers to the latest version to mitigate the vulnerability.
- Timeline: Ongoing since July 2025
Original Article Summary
Russian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform. Laundry Bear (also known as Void Blizzard, CL-STA-1114, and TA488) has been running the campaign since July 2025, according to a joint advisory from the NSA, FBI, CISA, and cybersecurity agencies from the Netherlands, UK, Australia, Canada, and a dozen other countries. “Laundry Bear’s … More → The post Russian hackers exploit unpatched Zimbra servers to steal emails appeared first on Help Net Security.
Impact
Zimbra Collaboration Suite (ZCS)
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since July 2025
Remediation
Organizations should immediately patch their Zimbra servers to the latest version to mitigate the vulnerability. Regularly check for software updates and apply them promptly.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Exploit, Vulnerability, Data Breach.