Exploited in the wild Zimbra Collaboration Suite Laundry Bear nation-state Zimbra Void Blizzard
Western cyber agencies warn of Russian hacks of Zimbra servers
CVE Tools coverage
Western cybersecurity agencies have issued warnings about a Russian hacking campaign exploiting a zero-day vulnerability in Zimbra Collaboration Suite. The flaw, CVE-2025-66376, allows attackers to inject malicious code into webmail clients through CSS @import, enabling credential theft and data exfiltration. The threat group behind the attacks is linked to Laundry Bear (also known as Void Blizzard or TA488), with evidence of extensive targeting of Ukrainian and NATO-related organizations.