Command Palette
Search for a command to run...

Russian Hacker Group Exploits Zimbra Email Flaw to Steal 90 Days of US and Ukrainian Data

techcybersecurityworldrussiaukraine 6 posts · 5 accounts

A Russian state-sponsored group identified as Laundry Bear is exploiting a vulnerability in the Zimbra Collaboration Suite email platform to steal data from U.S. and Ukrainian government, defense, and scientific organizations. The campaign leverages a malicious JavaScript payload that triggers when a user opens or previews an email in a webmail client, requiring no clicks or attachment downloads. The group collects up to 90 days of email data and sends it to attacker-controlled infrastructure.

The security flaw, tracked as CVE-2025-66376, was patched in November 2025, but unpatched servers remain exposed. U.S. officials and cyber authorities from more than a dozen countries warned of the operation on Thursday, revealing that data theft has been ongoing since July 2025. Intelligence gathered from the targeted organizations appears focused on nuclear fusion technology and defense capabilities to support military operations in Ukraine.

From the sources (6 posts)

@snlyngaas

Alleged Russian state-sponsored hackers target the emails of US nuclear scientists and defense contractors for strategic intelligence amid Ukraine, Iran wars:

@zcohencnn

"Their targets suggested an interest in nuclear fusion technology and intelligence that may aid in the Kremlin’s war with Ukraine."

@snlyngaas

RT @ZcohenCNN: "Their targets suggested an interest in nuclear fusion technology and intelligence that may aid in the Kremlin’s war with Uk…

@cyberscoopnews

Russian state-sponsored threat group has been stealing sensitive data from governments and commercial organizations since July 2025 via a novel exploit in popular Linux-based enterprise software, U.S. authorities and cyber officials from mo

@huntio

🚨 Laundry Bear Targets US and Ukraine Through Zimbra Russian state-backed group Laundry Bear is exploiting the Zimbra zero-day CVE-2025-66376 to target US and Ukrainian government, defense, and scientific organizat

@daveaitel

Xss is often used by real hackers. Annoying, but true.

Preview built on a synthetic news corpus (16 weeks, Apr–Jul 2026). Impact calls are model reads, not price data.

About Archive