Russian hackers exploit Zimbra zero-click flaw for email theft
CISA is warning that the Russian state-sponsored group Laundry Bear, also known as Void Blizzard, is targeting organizations that run Zimbra Collaboration…
By Dillip Chowdary • Aug 07, 2026 • Source: BleepingComputer
CISA is warning that the Russian state-sponsored group Laundry Bear, also known as Void Blizzard, is targeting organizations that run Zimbra Collaboration email servers. The campaign pairs phishing with exploitation of a now-patched Zimbra flaw and aims at email theft. BleepingComputer reported the alert.
The attack chain is hybrid rather than pure remote code execution. Operators use phishing to get a foothold or user interaction path, then exploit a zero-click Zimbra vulnerability so mail can be stolen without further clicks once the server is in scope. The vulnerability is already patched; unpatched or slowly patched Zimbra Collaboration instances remain the practical target.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
For engineers and builders, this matters if mail is hosted on self-managed Zimbra rather than a fully managed SaaS stack. Email is high-value for credential reuse, session tokens, and business data. A zero-click server-side path raises the cost of delay: patch lag on Collaboration hosts turns a known, fixed issue into an active theft channel when combined with phishing.
The market context is familiar for enterprise mail platforms: state-linked groups keep pressure on widely deployed, internet-facing collaboration stacks. Zimbra sits in that class of on-prem and self-hosted mail software that many orgs still run for control or cost. Laundry Bear / Void Blizzard fits the pattern of Russian-linked actors that mix social engineering with patched-but-lingering product bugs rather than only relying on brand-new zero-days.
Practical takeaway: treat Zimbra Collaboration patch status as a security control, not a maintenance chore, and assume phishing plus post-patch exploitation is an active model for this actor. Watch for CISA and vendor guidance on residual exposure, confirm all Collaboration hosts are on the fixed build, and review mail-access logs and phishing defenses for signs of Void Blizzard / Laundry Bear activity against any still-vulnerable estate.
Advertisement
🔎 More interesting news
- Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
- ByteDance aims to rival Anthropic with new model reaching up to 10T parameters
- Indirect Prompt Injection Exploits GitHub's AI Agent to Leak Private Repository Data
- Show HN: Echo – Fable-level results at 1/3 the cost using open-weight models
- Today's full Tech Pulse briefing →