trade-press
Russian Zero-Click Zimbra Exploit Steals Government Emails
Zimbra's smaller government footprint means fewer eyes on the logs, and this is the third zero-click nation-state email campaign in 18 months.
U.S. cyber agencies warned Thursday that Russian state-backed group Laundry Bear is exploiting a zero-click vulnerability in Zimbra Collaboration Suite that requires only that a victim open or preview a malicious email, no link click, no download. Active since July 2025, the campaign has hit more than 10 organizations across the defense industrial base, federal and local government, law enforcement, and other sectors. The exploit steals email archives up to 90 days, passwords, and two-factor authentication tokens. Zimbra's smaller government footprint compared with Exchange means these intrusions are less likely to be detected quickly.