← Back to Feed
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
July 23, 2026 · Dark Reading · Severity: CRITICAL
Russian state-sponsored threat group Laundry Bear (also known as APT28 or Fancy Bear) exploited a Zimbra zero-day vulnerability in targeted email campaigns against US government entities. The attack used half-click exploits — emails that require minimal user interaction such as viewing the message in a preview pane — to trigger the vulnerability and compromise mail servers without requiring the victim to open attachments or click links. This operational approach lowers the exploitation barrier significantly because it does not depend on end-user susceptibility to phishing, instead compromising the server directly through email processing logic.
Key Takeaways
- Russian APT group Laundry Bear exploited a Zimbra zero-day targeting US government entities via email.
- Half-click exploits require minimal user interaction, triggering the vulnerability via email preview rather than clicking.
- Server-side exploitation bypasses dependence on end-user susceptibility to traditional phishing techniques.