Russian Hackers Exploit Zero-Click Attack to Target Western Organizations
Russian state-supported hackers have launched a new cyber espionage campaign targeting Western organizations using a Zero-Click attack method. This technique, which does not require user interaction with phishing emails, has been used to compromise networks and gain persistent access. The campaign, identified as Laundry Bear, exploits a zero-day vulnerability in the Zimbra Collaboration Suite (ZCS) software, affecting sectors such as defense, government, education, energy, law enforcement, media, NGOs, and technology. The joint advisory was issued by the UK National Cyber Security Centre, US agencies including the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency, and the FBI, along with other Five Eyes nations and European agencies. The attack leverages a vulnerability disclosed in November 2025, using a zero-click exploit called 'beehive' to steal emails and sensitive data. Organizations using ZCS are urged to patch vulnerabilities and enhance network monitoring.