Russian Hackers Exploit Zimbra Zero-Day Flaw to Steal Emails and 2FA Codes
A Russian state-sponsored hacking group, known as Laundry Bear, has been exploiting a zero-day vulnerability in Zimbra Collaboration email servers to steal sensitive information. The flaw, identified as CVE-2025-66376, is a cross-site scripting vulnerability that allows attackers to execute JavaScript embedded in HTML emails automatically when viewed by the victim. This enables the theft of account data without user interaction. The group has targeted various sectors, including defense, government, education, and media, primarily focusing on organizations aligned with Russian strategic interests. The vulnerability was patched in November 2025, but unpatched servers remain at risk.