Western agencies warn of Russian zero-click attacks on Zimbra
This digest was compiled by AI from multiple sources — links to the originals are below.
Western intelligence agencies issued a joint advisory on July 23 warning that Russian state-backed hackers are exploiting a zero-day vulnerability in Zimbra Collaboration Suite to conduct zero-click attacks. The campaign, attributed to the Laundry Bear group, targets government and commercial organizations across multiple sectors to steal emails and maintain persistent access.
The Vulnerability
The attacks exploit CVE-2025-66376, a zero-day vulnerability in Zimbra Collaboration Suite publicly disclosed in November 2025. The zero-click exploit, dubbed 'beehive', allows attackers to compromise networks without user interaction—simply viewing a malicious email in a vulnerable webmail client triggers the attack. Successful exploitation enables exfiltration of at least the last 90 days of emails and other sensitive data.
Targeted Sectors
Organizations in defense, government, education, energy, law enforcement, media, NGO, and technology sectors have been identified as targets. The campaign has been active since at least July 2025, according to the advisory. The attackers also seek to maintain persistence by stealing passwords and bypassing multi-factor authentication via session tokens.
International Response
The advisory was issued by the UK National Cyber Security Centre, US agencies including CISA, NSA, and FBI, along with cyber agencies from Canada, Australia, New Zealand, and European partners. Beth Hopkins, COO of the NCSC, urged organizations to familiarize themselves with zero-click techniques and apply mitigations. System administrators are advised to patch the vulnerability immediately and monitor for suspicious activity.
What's Next
Organizations using Zimbra are urged to apply patches and enhance network monitoring. It remains unclear how many entities have been compromised or whether the exploit will be adapted for other platforms.
1 source
Western agencies warn of Russian zero-click attacks on Zimbra




