Top stories.
- Russia's Laundry Bear targets unpatched Zimbra servers.
- US State Department places visa restrictions on suspected cybercriminals.
- Stadler Rail refuses to pay ransomware gang.
Russia's Laundry Bear targets unpatched Zimbra servers.
US intelligence agencies, alongside their Five Eyes allies and partners in Europe, yesterday issued an advisory warning of a Russian state-sponsored phishing campaign targeting Western government and commercial entities using vulnerable versions of the Zimbra Collaboration Suite (ZCS). The campaign is attributed to a threat actor tracked as "Laundry Bear" or "Void Blizzard," whose goal is to harvest sensitive email data on behalf of the Russian government.
The threat actor began exploiting a Zimbra vulnerability (CVE-2025-66376) as a zero-day last year. The flaw was patched in November 2025, but Laundry Bear continues to successfully breach organizations that have not applied the patch.
Proofpoint says the flaw enables "half-click exploits," in which a user only needs to open the email in order for the exploit code to execute. Palo Alto Networks' Unit 42 explains that the phishing emails contain a JavaScript payload that injects into the victim's browser and exfiltrates the user's email credentials, CSRF tokens, 2FA scratch codes, system and environment details, and the victim's last 90 days of email and search history.

