← Back to Feed

Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

CVE-2025-66376

July 21, 2026 · CISA Cybersecurity Advisories · Severity: CRITICAL

This article describes a Russian state-sponsored phishing campaign targeting Zimbra Collaboration Suite users. The LAUNDRY BEAR group uses a view-based exploit that exfiltrates email data without user interaction. The vulnerability CVE-2025-66376 was a zero-day when first exploited and has since been patched.

Key Takeaways

  • Russian APT group LAUNDRY BEAR targets Zimbra Collaboration Suite users.
  • Exploit CVE-2025-66376 allows email exfiltration just by viewing malicious email.
  • The zero-day vulnerability was patched in November 2025 but still exploited.
☕ Buy a Coffee