← Back to Feed

Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets

July 23, 2026 · Dark Reading · Severity: CRITICAL

This article reports on a Russian state-sponsored hacking group, dubbed Laundry Bear, that is exploiting a Zimbra zero-day vulnerability to target organizations in the US and Ukraine. The group uses a unique 'half-click' phishing technique, where merely opening or previewing an email can trigger the exploit. This approach significantly lowers the barrier for a successful attack, as it requires no further user interaction beyond a simple preview.

Key Takeaways

  • State-sponsored group Laundry Bear exploits Zimbra zero-day against US and Ukraine targets.
  • Phishing emails require only a half-click, such as opening or previewing the message.
  • This low-friction attack vector increases the likelihood of successful compromise.
☕ Buy a Coffee