Home / Blog / Russian hackers exploit Zimbra zero-click flaw for email…
Tech News

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored group Laundry Bear, also known as Void Blizzard, is targeting organizations that run Zimbra Collaboration…

By Dillip Chowdary • Aug 07, 2026 • Source: BleepingComputer

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored group Laundry Bear, also known as Void Blizzard, is targeting organizations that run Zimbra Collaboration email servers. The campaign pairs phishing with exploitation of a now-patched Zimbra flaw and aims at email theft. BleepingComputer reported the alert.

The attack chain is hybrid rather than pure remote code execution. Operators use phishing to get a foothold or user interaction path, then exploit a zero-click Zimbra vulnerability so mail can be stolen without further clicks once the server is in scope. The vulnerability is already patched; unpatched or slowly patched Zimbra Collaboration instances remain the practical target.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

For engineers and builders, this matters if mail is hosted on self-managed Zimbra rather than a fully managed SaaS stack. Email is high-value for credential reuse, session tokens, and business data. A zero-click server-side path raises the cost of delay: patch lag on Collaboration hosts turns a known, fixed issue into an active theft channel when combined with phishing.

The market context is familiar for enterprise mail platforms: state-linked groups keep pressure on widely deployed, internet-facing collaboration stacks. Zimbra sits in that class of on-prem and self-hosted mail software that many orgs still run for control or cost. Laundry Bear / Void Blizzard fits the pattern of Russian-linked actors that mix social engineering with patched-but-lingering product bugs rather than only relying on brand-new zero-days.

Practical takeaway: treat Zimbra Collaboration patch status as a security control, not a maintenance chore, and assume phishing plus post-patch exploitation is an active model for this actor. Watch for CISA and vendor guidance on residual exposure, confirm all Collaboration hosts are on the fixed build, and review mail-access logs and phishing defenses for signs of Void Blizzard / Laundry Bear activity against any still-vulnerable estate.

Advertisement

🔎 More interesting news

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →