CVE Tools
Back to feed
Exploited in the wild Zimbra Collaboration Suite Laundry Bear nation-state Zimbra Void Blizzard

Russian hackers exploit Zimbra zero-click flaw for email theft

BleepingComputer·By Lawrence Abrams··3 min read
CVE Tools coverage

CISA has issued a warning that the Russian state-backed hacking group Laundry Bear, also known as Void Blizzard, is exploiting a recently patched vulnerability in Zimbra Collaboration Suite to conduct email theft campaigns. The flaw, tracked as CVE-2025-66376, is a cross-site scripting (XSS) issue in the Classic UI of the software. This allows attackers to inject malicious JavaScript into HTML emails, which executes automatically when viewed—enabling silent data exfiltration without user interaction. The threat actors have targeted multiple sectors, including defense, government, education, and technology, using this zero-click exploit alongside phishing techniques to steal sensitive information such as emails, passwords, and two-factor authentication tokens.