CISA, the National Security Agency (NSA) and the FBI published joint advisory AA26-204A on Thursday 23 July, co-sealed by fifteen partner agencies including Britain's NCSC, France's ANSSI and the Dutch AIVD, naming Russian state-supported actor LAUNDRY BEAR behind a zero-click exploit of Zimbra Collaboration Suite (ZCS) webmail 1.
Merely viewing a single email hands the actor the victim's last 90 days of mail and the organisation's Global Address List (GAL), the internal directory of every staff name and address. The chain abuses CVE-2025-66376, a common vulnerabilities and exposures (CVE) flaw Zimbra patched in November 2025, so every still-exposed appliance has run eight months unpatched.
LAUNDRY BEAR, tracked elsewhere as Void Blizzard and CL-STA-1114, drew a Dutch intelligence attribution in May 2025 for password-spraying and pass-the-cookie theft against cloud email. The exploit now fires the moment a target previews the message, removing the human-error step that awareness training targets. The advisory warns it will pivot to other webmail platforms as ZCS patching climbs, so fixing the appliance closes only today's door.
Fifteen co-sealing agencies is an unusually broad coalition; the FSB Centre 16 router-hijacking advisory two weeks earlier carried eighteen , against the two to four names a routine attribution once bore. The advisory format is scaling to match the breadth of Western email systems inside the blast radius.
