The Cybersecurity and Infrastructure Security Agency (CISA), alongside the FBI and NSA, has issued an urgent warning regarding a Russian hacking campaign targeting unpatched Zimbra Collaboration Suite servers. The group, known as Laundry Bear, exploits a security flaw to steal up to 90 days of emails, passwords, and authentication tokens from victims simply by having them view a malicious message.
How does the Zimbra email exploit work?
The attack leverages a cross-site scripting vulnerability, tracked as CVE-2025-66376, within the Zimbra Collaboration Suite. Hackers embed malicious JavaScript into emails, which executes automatically when a user views or previews the message. This allows attackers to bypass traditional phishing defenses, harvesting sensitive data like authentication tokens and recent email history without requiring the user to click any links or attachments.
Who is at risk from the Laundry Bear campaign?
Since July 2025, the Laundry Bear group has targeted over 10 Western organizations, including government agencies, educational institutions, and defense contractors. Because the exploit targets unpatched servers, any organization running older versions of the Zimbra software remains at high risk. Security officials urge administrators to verify their system patches immediately, as the hackers can maintain persistent access by creating unauthorized application passcodes even after the initial breach.