Russian Espionage Group Exploits Zimbra Vulnerability to Steal Data from Western Nations
A Russian state-sponsored cyber espionage group, known as Laundry Bear, has been exploiting a zero-day vulnerability in the Zimbra Collaboration Suite to steal sensitive data from Western governments and organizations. This campaign, which began in July 2025, involves a novel exploit that allows attackers to access emails, passwords, and other sensitive information without user interaction. The vulnerability was not patched until November 2025, allowing the group to conduct espionage activities with Russian government backing. The group has targeted sectors including defense, education, energy, and finance, with a focus on Ukrainian users before expanding to U.S. and NATO allies.