A joint advisory from CISA, the NSA, FBI and international partners warns that a Russian state-backed hacking group known as LAUNDRY BEAR has been exploiting a flaw in Zimbra Collaboration Suite to steal email since mid-2025.
- What it is: A zero-click vulnerability (CVE-2025-66376) in Zimbra email software. Simply viewing a malicious email is enough to trigger it – no link or attachment needs to be opened.
- Who is affected: Organisations running unpatched Zimbra Collaboration Suite. Government, defence, education, energy and technology sector targets have been hit, but any Zimbra user is at risk.
- What the risk is: Attackers can silently steal up to 90 days of email history, contact directories, and stored app passwords.
- What action is needed: Update Zimbra Collaboration Suite to version 10.1.13, 10.0.18, or later immediately if your business runs this platform.
If you are unsure which email platform your business runs, we recommend checking with your IT provider today rather than assuming you are unaffected.
Source: CISA Advisory AA26-204A