Russian Cyber Attacks Exploit Email Vulnerability to Steal Sensitive Data
A year-long cyber attack campaign by Russian hackers, identified as Laundry Bear, has been exploiting a vulnerability in the Zimbra email platform. The attack, which requires no user interaction beyond viewing a malicious email, has been ongoing since July 2025. It targets a cross-site scripting vulnerability in Zimbra, allowing attackers to inject malicious JavaScript into web pages. The campaign has affected various sectors, including defense, government, education, and technology. The attackers exfiltrate sensitive data such as email communications, passwords, and authentication tokens. The stolen data is stored on a virtual private server using a custom framework called Flowerbed.