← Back to Feed
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
July 23, 2026 · Dark Reading · Severity: CRITICAL
Russian state-sponsored threat group Laundry Bear (also known as APT28 or Fancy Bear) exploited a Zimbra zero-day vulnerability in targeted email campaigns against US government entities. The attack used half-click exploits — emails that require minimal user interaction such as viewing the message in a preview pane — to trigger the vulnerability and compromise mail servers without requiring the victim to open attachments or click links. This operational approach lowers the exploitation barrier significantly because it does not depend on end-user susceptibility to phishing, instead compromising the server directly through email processing logic.
Key Takeaways
- A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that.
- A state-sponsored threat group, dubbed "Laundry Bear," sends "half-click" phishing emails that require a victim only to open or preview the message.