Russian APT group exploits zero-click vulnerability in Zimbra (CVE-2025-66376) (heise.de)
- Russian APT group Laundry Bear exploits zero-click vulnerability (CVE-2025-66376) in Zimbra since July 2025.
- Targets include Western governments, energy, education, law enforcement, media, NGOs, and tech sectors.
- No user interaction required; email preview triggers compromise.
- Patch available since November 2025, but many servers unpatched; BSI reported 40% of German Zimbra servers vulnerable.
- Latest version Zimbra 10.1.20 fixes multiple additional vulnerabilities.
"Since July 2025, Russian APT group Laundry Bear (a.k.a. Void Blizzard) has been exploiting a zero-click vulnerability in Zimbra Collaboration Suite (CVE-2025-66376, CVSS 7.2) to target Western governments, energy, education, law enforcement, media, NGOs, and tech sectors. The exploit requires no user interaction; viewing an email is sufficient. A patch has been available since November 2025, but many servers remain unpatched. Germany's BSI reported that about 40% of German Zimbra servers are vulnerable. CISA and other agencies urge immediate updates to Zimbra 10.1.20, which also fixes additional vulnerabilities."
no comments yet.