Russian Espionage Group Exploits Zimbra Flaw to Access Western Emails
A Russian state-supported espionage group has been exploiting a vulnerability in Zimbra's webmail client to access emails and two-factor authentication codes from Western organizations. The flaw, identified as CVE-2025-66376, is a stored cross-site scripting vulnerability that allows malicious HTML emails to execute JavaScript within authenticated webmail sessions. This exploit, which requires no user interaction beyond viewing the email, has been used to target government and commercial organizations in NATO member states, Ukraine, and the U.S., among others. The group, tracked by Proofpoint as TA488, has been active since at least July 2025, using the vulnerability to steal sensitive information and credentials.