0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

Russian APT group exploits zero-click vulnerability in Zimbra (CVE-2025-66376) (heise.de)

· 4d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Russian APT group Laundry Bear exploits zero-click vulnerability (CVE-2025-66376) in Zimbra since July 2025.
  • Targets include Western governments, energy, education, law enforcement, media, NGOs, and tech sectors.
  • No user interaction required; email preview triggers compromise.
  • Patch available since November 2025, but many servers unpatched; BSI reported 40% of German Zimbra servers vulnerable.
  • Latest version Zimbra 10.1.20 fixes multiple additional vulnerabilities.

"Since July 2025, Russian APT group Laundry Bear (a.k.a. Void Blizzard) has been exploiting a zero-click vulnerability in Zimbra Collaboration Suite (CVE-2025-66376, CVSS 7.2) to target Western governments, energy, education, law enforcement, media, NGOs, and tech sectors. The exploit requires no user interaction; viewing an email is sufficient. A patch has been available since November 2025, but many servers remain unpatched. Germany's BSI reported that about 40% of German Zimbra servers are vulnerable. CISA and other agencies urge immediate updates to Zimbra 10.1.20, which also fixes additional vulnerabilities."

Discussion Matrix

0 segments

no comments yet.