Exploited in the wild Zimbra Collaboration Suite Laundry Bear nation-state Zimbra APT28
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
CVE Tools coverage
Russian state-backed threat actors have been exploiting a critical zero-day vulnerability in Zimbra Collaboration Suite (CVE-2025-66376) to target U.S., Ukrainian, and other Western government and enterprise networks since July 2025. The flaw allows attackers to execute a so-called 'half-click' phishing attack—requiring only that a user view a malicious email within a vulnerable version of Zimbra webmail. This method bypasses traditional phishing defenses and enables adversaries to exfiltrate sensitive data. Multiple intelligence and cybersecurity agencies warn that the exploit is being used by the APT group Laundry Bear, with ties to Russian intelligence, to gather information for strategic advantage.