The Cybersecurity and Infrastructure Security Agency (CISA), the NSA and FBI led 15 nations in naming Russian group LAUNDRY BEAR on 23 July. It exploited a zero-click flaw in Zimbra webmail to read victims' email for up to 90 days without any click.
A patch existed eight months before the warning. Many self-hosted Zimbra servers never applied it, showing how slowly patches move once software leaves the vendor's direct control.
