← Back to Feed
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
July 23, 2026 · Dark Reading · Severity: CRITICAL
This article reports on a Russian state-sponsored hacking group, dubbed Laundry Bear, that is exploiting a Zimbra zero-day vulnerability to target organizations in the US and Ukraine. The group uses a unique 'half-click' phishing technique, where merely opening or previewing an email can trigger the exploit. This approach significantly lowers the barrier for a successful attack, as it requires no further user interaction beyond a simple preview.
Key Takeaways
- State-sponsored group Laundry Bear exploits Zimbra zero-day against US and Ukraine targets.
- Phishing emails require only a half-click, such as opening or previewing the message.
- This low-friction attack vector increases the likelihood of successful compromise.