Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

Zimbra preview leaks mail to Russia

2 min read
18:20UTC

CISA, the NSA and the FBI named Russian actor LAUNDRY BEAR behind a zero-click Zimbra flaw that reads 90 days of mail on a single preview, in an advisory fifteen agencies co-sealed.

TechnologyAssessed
Key takeaway

Fifteen nations named a Russian zero-click Zimbra exploit that fires on preview, beyond any awareness training.

CISA, the National Security Agency (NSA) and the FBI published joint advisory AA26-204A on Thursday 23 July, co-sealed by fifteen partner agencies including Britain's NCSC, France's ANSSI and the Dutch AIVD, naming Russian state-supported actor LAUNDRY BEAR behind a zero-click exploit of Zimbra Collaboration Suite (ZCS) webmail 1.

Merely viewing a single email hands the actor the victim's last 90 days of mail and the organisation's Global Address List (GAL), the internal directory of every staff name and address. The chain abuses CVE-2025-66376, a common vulnerabilities and exposures (CVE) flaw Zimbra patched in November 2025, so every still-exposed appliance has run eight months unpatched.

LAUNDRY BEAR, tracked elsewhere as Void Blizzard and CL-STA-1114, drew a Dutch intelligence attribution in May 2025 for password-spraying and pass-the-cookie theft against cloud email. The exploit now fires the moment a target previews the message, removing the human-error step that awareness training targets. The advisory warns it will pivot to other webmail platforms as ZCS patching climbs, so fixing the appliance closes only today's door.

Fifteen co-sealing agencies is an unusually broad coalition; the FSB Centre 16 router-hijacking advisory two weeks earlier carried eighteen , against the two to four names a routine attribution once bore. The advisory format is scaling to match the breadth of Western email systems inside the blast radius.

Deep Analysis

In plain English

Zimbra Collaboration Suite is email software that organisations run on their own servers instead of using a service like Gmail. A flaw in it, tracked as CVE-2025-66376, let attackers read someone's email just by having it appear in their inbox, without the victim clicking anything. A hacking group Western governments call LAUNDRY BEAR, working on behalf of Russia, used this flaw to read and copy emails from targets for up to three months at a time. On 23 July, 15 countries led by the US cyber agency CISA, the NSA and the FBI jointly published a warning naming LAUNDRY BEAR and explaining how the attack worked, so organisations still running unpatched Zimbra servers know to fix them immediately.

Deep Analysis
Root Causes

The zero-click chain depended on Zimbra's self-hosted deployment model: unlike SaaS webmail, patching CVE-2025-66376 required each organisation's own IT team to apply the fix, and CISA's figures show many did not for eight months after it shipped.

A second structural gap is verification lag: zero-click delivery meant victims had no phishing click or malicious attachment to alert defenders, so mail exfiltration could run for up to 90 days before detection tools built for user-triggered compromise caught the activity.

Escalation

The 15-agency signature count is itself an escalation signal: joint advisories of this scale are reserved for actors governments want publicly deterred, not merely technically documented.

What could happen next?
  • Meaning

    A 15-agency joint attribution list signals Western governments shifting toward public, coordinated naming of Russian state-linked actors rather than quiet technical warnings.

  • Risk

    Organisations still running unpatched Zimbra Collaboration Suite deployments remain exposed to the same zero-click chain until they apply the CVE-2025-66376 fix.

First Reported In

Update #11 · Zimbra zero-click, and a 15-nation reply

CISA· 24 Jul 2026
Read original
Causes and effects
This Event
Zimbra preview leaks mail to Russia
A preview-triggered exploit removes the user-error step defensive training relies on, leaving patch speed on the webmail appliance as the only working control.
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.