Russian hackers exploit Zimbra zero-click flaw for email theft
CISA has issued a warning that the Russian state-backed hacking group Laundry Bear, also known as Void Blizzard, is exploiting a recently patched vulnerability in Zimbra Collaboration Suite to conduct email theft campaigns. The flaw, tracked as CVE-2025-66376, is a cross-site scripting (XSS) issue in the Classic UI of the software. This allows attackers to inject malicious JavaScript into HTML emails, which executes automatically when viewed—enabling silent data exfiltration without user interaction. The threat actors have targeted multiple sectors, including defense, government, education, and technology, using this zero-click exploit alongside phishing techniques to steal sensitive information such as emails, passwords, and two-factor authentication tokens.