CVE Tools
Back to feed
Exploited in the wild Zimbra Collaboration Suite Laundry Bear nation-state Zimbra Void Blizzard

Western cyber agencies warn of Russian hacks of Zimbra servers

Risky Business News·By Catalin Cimpanu··2 min read
CVE Tools coverage

Western cybersecurity agencies have issued warnings about a Russian hacking campaign exploiting a zero-day vulnerability in Zimbra Collaboration Suite. The flaw, CVE-2025-66376, allows attackers to inject malicious code into webmail clients through CSS @import, enabling credential theft and data exfiltration. The threat group behind the attacks is linked to Laundry Bear (also known as Void Blizzard or TA488), with evidence of extensive targeting of Ukrainian and NATO-related organizations.