Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
3AUG

Zimbra preview leaks mail to Russia

2 min read
16:08UTC

CISA, the NSA and the FBI named Russian actor LAUNDRY BEAR behind a zero-click Zimbra flaw that reads 90 days of mail on a single preview, in an advisory fifteen agencies co-sealed.

TechnologyAssessed
Key takeaway

Fifteen nations named a Russian zero-click Zimbra exploit that fires on preview, beyond any awareness training.

CISA, the National Security Agency (NSA) and the FBI published joint advisory AA26-204A on Thursday 23 July, co-sealed by fifteen partner agencies including Britain's NCSC, France's ANSSI and the Dutch AIVD, naming Russian state-supported actor LAUNDRY BEAR behind a zero-click exploit of Zimbra Collaboration Suite (ZCS) webmail 1.

Merely viewing a single email hands the actor the victim's last 90 days of mail and the organisation's Global Address List (GAL), the internal directory of every staff name and address. The chain abuses CVE-2025-66376, a common vulnerabilities and exposures (CVE) flaw Zimbra patched in November 2025, so every still-exposed appliance has run eight months unpatched.

LAUNDRY BEAR, tracked elsewhere as Void Blizzard and CL-STA-1114, drew a Dutch intelligence attribution in May 2025 for password-spraying and pass-the-cookie theft against cloud email. The exploit now fires the moment a target previews the message, removing the human-error step that awareness training targets. The advisory warns it will pivot to other webmail platforms as ZCS patching climbs, so fixing the appliance closes only today's door.

Fifteen co-sealing agencies is an unusually broad coalition; the FSB Centre 16 router-hijacking advisory two weeks earlier carried eighteen , against the two to four names a routine attribution once bore. The advisory format is scaling to match the breadth of Western email systems inside the blast radius.

Deep Analysis

In plain English

Zimbra Collaboration Suite is email software that organisations run on their own servers instead of using a service like Gmail. A flaw in it, tracked as CVE-2025-66376, let attackers read someone's email just by having it appear in their inbox, without the victim clicking anything. A hacking group Western governments call LAUNDRY BEAR, working on behalf of Russia, used this flaw to read and copy emails from targets for up to three months at a time. On 23 July, 15 countries led by the US cyber agency CISA, the NSA and the FBI jointly published a warning naming LAUNDRY BEAR and explaining how the attack worked, so organisations still running unpatched Zimbra servers know to fix them immediately.

Deep Analysis
Root Causes

The zero-click chain depended on Zimbra's self-hosted deployment model: unlike SaaS webmail, patching CVE-2025-66376 required each organisation's own IT team to apply the fix, and CISA's figures show many did not for eight months after it shipped.

A second structural gap is verification lag: zero-click delivery meant victims had no phishing click or malicious attachment to alert defenders, so mail exfiltration could run for up to 90 days before detection tools built for user-triggered compromise caught the activity.

Escalation

The 15-agency signature count is itself an escalation signal: joint advisories of this scale are reserved for actors governments want publicly deterred, not merely technically documented.

What could happen next?
  • Meaning

    A 15-agency joint attribution list signals Western governments shifting toward public, coordinated naming of Russian state-linked actors rather than quiet technical warnings.

  • Risk

    Organisations still running unpatched Zimbra Collaboration Suite deployments remain exposed to the same zero-click chain until they apply the CVE-2025-66376 fix.

First Reported In

Update #11 · Zimbra zero-click, and a 15-nation reply

CISA· 24 Jul 2026
Read original
Causes and effects
This Event
Zimbra preview leaks mail to Russia
A preview-triggered exploit removes the user-error step defensive training relies on, leaving patch speed on the webmail appliance as the only working control.
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.